| Bug | Description | Note |
|---|
| CVE-2016-1584 | In all versions of Unity8 a running but not active application on a la ... | check proper tracking update |
| CVE-2018-25246 | Wikipedia 12.0 contains a denial of service vulnerability that allows ... | check |
| CVE-2018-25305 | librsvg2-bin 2.40.13 contains a buffer overflow vulnerability that all ... | check |
| CVE-2018-25306 | PDFunite 0.41.0 contains a buffer overflow vulnerability that allows l ... | check |
| CVE-2019-25485 | R 3.4.4 on Windows x64 contains a buffer overflow vulnerability in the ... | check |
| CVE-2019-25683 | FileZilla 3.40.0 contains a denial of service vulnerability in the loc ... | check |
| CVE-2022-4996 | A flaw has been found in mruby 3.1.0. Affected is the function udiv of ... | check |
| CVE-2022-23538 | github.com/sylabs/scs-library-client is the Go client for the Singular ... | check details, might as well affect golang-github-apptainer-container-library-client |
| CVE-2022-50942 | Incinga Web 2.8.2 contains a client-side cross-site scripting vulnerab ... | check status upstream |
| CVE-2023-26044 | react/http is an event-driven, streaming HTTP client and server implem ... | check, is embedded inicinga-php-thirdparty, icingaweb2-module-reactbundle possibly affected |
| CVE-2023-47268 | In libslic3r/GCode/PostProcessor.cpp in Prusa PrusaSlicer through 2.6. ... | check |
| CVE-2023-49316 | In Math/BinaryField.php in phpseclib 3 before 3.0.34, excessively larg ... | check if affecting ldap-account-manager or unused path |
| CVE-2023-50251 | php-svg-lib is an SVG file parsing / rendering library. Prior to versi ... | check, other packages are embedding the library: civicrm, icinga-php-thirdparty and icingaweb2 to be checked |
| CVE-2023-50252 | php-svg-lib is an SVG file parsing / rendering library. Prior to versi ... | check, other packages are embedding the library: civicrm, icinga-php-thirdparty and icingaweb2 to be checked |
| CVE-2023-50262 | Dompdf is an HTML to PDF converter for PHP. When parsing SVG images Do ... | check sources embedding php-dompdf if affected |
| CVE-2024-7708 | For requests that have a body, but reading the body may end up in read ... | check |
| CVE-2024-22420 | JupyterLab is an extensible environment for interactive and reproducib ... | check completeness, src:jupyter-notebook? |
| CVE-2024-22421 | JupyterLab is an extensible environment for interactive and reproducib ... | check completeness, src:jupyter-notebook? |
| CVE-2024-54192 | An issue inTcpreplay v4.5.1 allows a local attacker to cause a denial ... | check |
| CVE-2025-4382 | A flaw was found in systems utilizing LUKS-encrypted disks with GRUB c ... | double check if vulnerability only considered present after grub_is_cli_disabled is introduced |
| CVE-2025-6499 | A vulnerability classified as problematic was found in vstakhov libucl ... | check if impacts security wise rspamd, which embeds libucl and uses it a compile time |
| CVE-2025-8671 | A mismatch caused by client-triggered server-sent stream resets betwee ... | check, some projects will assign own CVEs and should then be covered under that specific CVE instead |
| CVE-2025-8941 | A flaw was found in linux-pam. The pam_namespace module may improperly ... | check likely RedHat specific incomplete fix for CVE-2025-6020, but asked to pinpoint incomplete fixes |
| CVE-2025-11010 | A vulnerability has been found in vstakhov libucl up to 0.9.2. Affecte ... | check if impacts security wise rspamd, which embeds libucl and uses it a compile time |
| CVE-2025-11147 | Reflected cross-site scripting (XSS) in Apt-Cacher-NG v3.2.1. The vuln ... | clarifying with reporter and Eduard Bloch on the issue. |
| CVE-2025-11395 | A flaw was found in Podman. If an attacker can pass a crafted tar arch ... | check |
| CVE-2025-14575 | An Uncontrolled Search Path Element vulnerability in the OpenSSL TLS b ... | check |
| CVE-2025-15569 | A flaw has been found in Artifex MuPDF up to 1.26.1 on Windows. The im ... | check |
| CVE-2025-33221 | NVIDIA Display Driver for Windows and Linux contains a vulnerability i ... | check |
| CVE-2025-58064 | CKEditor 5 is a modern JavaScript rich-text editor with an MVC archite ... | check |
| CVE-2025-59953 | LMDeploy is a toolkit for compressing, deploying, and serving large la ... | check |
| CVE-2025-60796 | phpPgAdmin 7.13.0 and earlier contains multiple cross-site scripting ( ... | check, possibly not reported upstream |
| CVE-2025-60797 | phpPgAdmin 7.13.0 and earlier contains a SQL injection vulnerability i ... | check, possibly not reported upstream |
| CVE-2025-60798 | phpPgAdmin 7.13.0 and earlier contains a SQL injection vulnerability i ... | check, possibly not reported upstream |
| CVE-2025-60799 | phpPgAdmin 7.13.0 and earlier contains an incorrect access control vul ... | check, possibly not reported upstream |
| CVE-2025-61261 | A reflected cross-site scripting (XSS) vulnerability in CKeditor v46.1 ... | check |
| CVE-2025-61982 | An arbitrary code execution vulnerability exists in the Code Stream di ... | check upstream status |
| CVE-2025-63842 | A Cross-Site Scripting (XSS) vulnerability in the web backend for the ... | check |
| CVE-2025-66578 | xmlseclibs is a library written in PHP for working with XML Encryption ... | check |
| CVE-2025-67108 | eProsima Fast-DDS v3.3 was discovered to contain improper validation f ... | check https://gist.github.com/lkloliver/81b5d5a8328d712dbfd497bf11dbe913, unclear if reported upstream |
| CVE-2025-69534 | Python-Markdown version 3.8 contain a vulnerability where malformed HT ... | Asking whether it really needs a backport: https://bugs.debian.org/1131896 |
| CVE-2025-69720 | The infocmp command-line tool in ncurses before 6.5-20251213 has a sta ... | check upstream status |
| CVE-2025-69969 | A lack of authentication and authorization mechanisms in the Bluetooth ... | check |
| CVE-2025-70887 | An issue in ralphje Signify before v.0.9.2 allows a remote attacker to ... | check |
| CVE-2026-0708 | A flaw was found in libucl. A remote attacker could exploit this by pr ... | check if impacts security wise rspamd, which embeds libucl and uses it a compile time |
| CVE-2026-1703 | When pip is installing and extracting a maliciously crafted wheel arch ... | check as well pipenv |
| CVE-2026-4833 | A weakness has been identified in Orc discount up to 3.0.1.2. This iss ... | check libtext-markdown-discount-perl, ruby-rdiscount, cantor, embedding discount; check if security impact present |
| CVE-2026-5422 | A path traversal vulnerability exists in jupyter-server version 2.17.0 ... | CNA contacted responsible for this CVE entry as this seems to be a duplicate of CVE-2026-35397 |
| CVE-2026-6657 | A vulnerability in jupyter-server versions 1.12.0 through 2.17.0 allow ... | CNA contacted responsible for this CVE entry as this seems to be a duplicate of CVE-2026-40110 |
| CVE-2026-7701 | A security vulnerability has been detected in Telegram Desktop up to 6 ... | check upstream reports |
| CVE-2026-7790 | Uncontrolled Resource Consumption vulnerability in ninenines cowlib (c ... | check if embedded copy in rabbitmq-server is problematic |
| CVE-2026-8462 | SQL injection in ClickHouse-backed meter definitions in OpenMeter Open ... | check |
| CVE-2026-8851 | SOGo versions 5.12.7 and prior contains a SQL injection vulnerability ... | check correctness |
| CVE-2026-8863 | Multiple Microsoft-sigend UEFI SHIM bootloaders are vulnerable to Secu ... | check |
| CVE-2026-10051 | In Eclipse Jetty, a first HTTP/1.1 request with trailers causes the se ... | check, jetty9 might not be affected as not explicitly mentioned in the GhSA and still supported |
| CVE-2026-10144 | Rsbuild before 2.0.9 contains a command injection vulnerability that a ... | check |
| CVE-2026-10528 | A security flaw has been discovered in Orthanc DICOM Server up to 1.12 ... | check, uderlying issue in src:dcmtk and should the CVE be associated with it? Cf. #1138713 |
| CVE-2026-12611 | A client may issue HTTP/2 requests to a Jetty server that result in bl ... | check, GHSA reference not yet public |
| CVE-2026-13326 | An out-of-bounds read in Qt NFC's language code length parsing allows ... | check |
| CVE-2026-14916 | A JWT signature verification vulnerability affects Kong components tha ... | check |
| CVE-2026-14917 | A SAML authentication bypass vulnerability affects the Kong SAML plugi ... | check |
| CVE-2026-15779 | A flaw was found in samba's pam_winbind. When mkhomedir is enabled, pa ... | check if Red Hat specific |
| CVE-2026-18358 | A flaw was found in gnome-remote-desktop as shipped in Red Hat Enterpr ... | does not affect an upstream version, but need to check if still only Red Hat specific, check details RH bug |
| CVE-2026-19201 | An uncontrolled recursion vulnerability in the Windows SIPA event log ... | check, GHSA not yet public, maybe Windows specific |
| CVE-2026-19203 | A client may issue specially crafted HTTP/1.1 chunked requests to a Je ... | check, GHSA reference not yet public |
| CVE-2026-19204 | A client may send a WebSocket frame with an unknown opcode and a very ... | check, GHSA reference not yet public |
| CVE-2026-19248 | QDomDocument XML parsing is vulnerable to a remotely-triggerable denia ... | check |
| CVE-2026-19504 | Fabric.js loadFromJSON Server-Side Request Forgery Vulnerability. This ... | check |
| CVE-2026-19607 | A flaw was found in the first-broker-login flow of the keycloak-servic ... | check |
| CVE-2026-19614 | The API is prone to XML external entity (XXE) injection. By default, X ... | check details as reference not accessible |
| CVE-2026-19773 | libwebsockets HTTP/2 HPACK Path Header Parsing Out-Of-Bounds Write Rem ... | check |
| CVE-2026-20331 | As part of Cisco's ongoing commitment to proactive security and produc ... | check |
| CVE-2026-20337 | A vulnerability in the zip archive parser of ClamAV could allow an una ... | check |
| CVE-2026-20338 | A vulnerability in the zip archive parser of ClamAV could allow an una ... | check |
| CVE-2026-22739 | Vulnerability in Spring Cloud when substituting the profile parameter ... | check |
| CVE-2026-23479 | Redis is an in-memory data structure store. In redis-server from 7.2.0 ... | check redict and valkey |
| CVE-2026-23631 | Redis is an in-memory data structure store. In all versions of redis-s ... | check redict and valkey |
| CVE-2026-24182 | NVIDIA Display Driver for Windows and Linux contains a vulnerability w ... | check |
| CVE-2026-24187 | NVIDIA Display Driver for Linux contains a vulnerability where an atta ... | check |
| CVE-2026-24190 | NVIDIA Display Driver for Windows and Linux contains a vulnerability i ... | check |
| CVE-2026-24192 | NVIDIA Display Driver for Linux contains a vulnerability where an atta ... | check |
| CVE-2026-24193 | NVIDIA Display Driver for Windows and Linux contains a vulnerability w ... | check |
| CVE-2026-24194 | NVIDIA Display Driver for Linux contains a vulnerability in a kernel m ... | check |
| CVE-2026-24195 | NVIDIA Display Driver for Linux contains a vulnerability in UVM, where ... | check |
| CVE-2026-24196 | NVIDIA Display Driver for Linux contains a vulnerability where a user ... | check |
| CVE-2026-24197 | NVIDIA Display Driver for Linux contains a vulnerability in the Multi- ... | check |
| CVE-2026-24198 | NVIDIA GPU Display Driver for Linux contains a vulnerability where an ... | check |
| CVE-2026-24199 | NVIDIA Display Driver for Linux contains a vulnerability in a kernel m ... | check |
| CVE-2026-25243 | Redis is an in-memory data structure store. In versions of redis-serve ... | check redict and valkey |
| CVE-2026-27546 | An unauthenticated remote attacker can exploit an authentication bypas ... | check |
| CVE-2026-27547 | A low-privileged remote attacker can exploit a command injection vulne ... | check |
| CVE-2026-27548 | A low-privileged remote attacker can exploit a command injection vulne ... | check |
| CVE-2026-27549 | A low-privileged remote attacker can exploit a command injection vulne ... | check |
| CVE-2026-27550 | A low-privileged remote attacker can exploit a command injection vulne ... | check |
| CVE-2026-27551 | A low-privileged remote attacker can exploit a command injection vulne ... | check |
| CVE-2026-27552 | A low-privileged remote attacker can exploit improper authorization in ... | check |
| CVE-2026-27553 | A low-privileged remote attacker can manipulate the schema path parame ... | check |
| CVE-2026-27554 | A low-privileged remote attacker can exploit a command injection vulne ... | check |
| CVE-2026-27555 | A low-privileged remote attacker can exploit a local file inclusion vu ... | check |
| CVE-2026-27556 | A low-privileged remote attacker can exploit a local file inclusion vu ... | check |
| CVE-2026-27557 | An unauthenticated remote attacker can exploit a path traversal vulner ... | check |
| CVE-2026-27558 | A low-privileged remote attacker can exploit a command injection vulne ... | check |
| CVE-2026-27559 | A low-privileged remote attacker can exploit a command injection vulne ... | check |
| CVE-2026-27560 | A high-privileged remote attacker can exploit a command injection vuln ... | check |
| CVE-2026-27561 | A high-privileged remote attacker can exploit a command injection vuln ... | check |
| CVE-2026-27562 | A high-privileged remote attacker can exploit a command injection vuln ... | check |
| CVE-2026-27563 | A high-privileged remote attacker can exploit a command injection vuln ... | check |
| CVE-2026-27564 | A high-privileged remote attacker can exploit a command injection vuln ... | check |
| CVE-2026-27565 | An unauthenticated remote attacker can upload a malicious IODD file th ... | check |
| CVE-2026-27970 | Angular is a development platform for building mobile and desktop web ... | check status for older versions |
| CVE-2026-28343 | CKEditor 5 is a modern JavaScript rich-text editor with an MVC archite ... | check |
| CVE-2026-29022 | dr_libs dr_wav.h version 0.14.4 and earlier (fixed in commit 8a7258c) ... | qtads, dosbox-x, roc-toolkit, octave-ltfat, faudio bundle a copy, check security impact |
| CVE-2026-29036 | cJSON versions 1.5.0 through 1.7.19 contain an incorrectly-resolved na ... | check, report upstream status |
| CVE-2026-30478 | A Dynamic-link Library Injection vulnerability in GatewayGeo MapServer ... | check |
| CVE-2026-30479 | A Dynamic-link Library Injection vulnerability in OSGeo Project MapSer ... | check |
| CVE-2026-31053 | A double free vulnerability exists in librz/bin/format/le/le.c in the ... | check |
| CVE-2026-32148 | Insufficient Verification of Data Authenticity vulnerability in hexpm ... | check |
| CVE-2026-32313 | xmlseclibs is a library written in PHP for working with XML Encryption ... | check |
| CVE-2026-32599 | Netmaker makes networks with WireGuard. Prior to version 1.5.0, the `s ... | check |
| CVE-2026-32600 | xml-security is a library that implements XML signatures and encryptio ... | check |
| CVE-2026-32635 | Angular is a development platform for building mobile and desktop web ... | check status for older versions |
| CVE-2026-34240 | JOSE is a Javascript Object Signing and Encryption (JOSE) library. Pri ... | check |
| CVE-2026-36499 | A missing upper-bound check in the udpif_set_threads() function of Ope ... | check, unclear status/validity |
| CVE-2026-38999 | A Null Pointer Dereference in the mk_sched_event_close function (mk_se ... | check |
| CVE-2026-39178 | A SQL injection vulnerability in SOGo before 5.12.7 allows authenticat ... | CVE-2026-39178 and CVE-2026-39179 are duplicates of CVE-2026-46445 and CVE-2026-46446, CNA contacted |
| CVE-2026-39179 | A SQL injection vulnerability in SOGo before 5.12.7 allows authenticat ... | CVE-2026-39178 and CVE-2026-39179 are duplicates of CVE-2026-46445 and CVE-2026-46446, CNA contacted |
| CVE-2026-39860 | Nix is a package manager for Linux and other Unix systems. A bug in th ... | check, potentially affecting guix if same issue in backporting fix for CVE-2024-2729 |
| CVE-2026-39919 | Ghostscript before 10.08.0 contains a heap-based buffer overflow vulne ... | check |
| CVE-2026-40033 | FreeRDP before 3.26.0 contains a heap-buffer-overflow vulnerability in ... | unclear fixing commit references, incorrect reference in CVE entry? |
| CVE-2026-41889 | pgx is a PostgreSQL driver and toolkit for Go. Prior to version 5.9.2, ... | check the other golang-github-jackc-pgx* sources |
| CVE-2026-42199 | Grid is a data structure grid for rust. From version 0.17.0 to before ... | check |
| CVE-2026-42308 | Pillow is a Python imaging library. Prior to version 12.2.0, if a font ... | research fixing commit(s), maybe https://github.com/python-pillow/Pillow/pull/9518/changes |
| CVE-2026-42503 | gopls by default communicates via pipe. However, -port and -listen fla ... | check impact on golang-golang-x-tools |
| CVE-2026-43627 | llama.cpp builds b1283 through b9058 contain an integer overflow vulne ... | check |
| CVE-2026-43628 | llama.cpp builds b3978 through b9058 contain an integer underflow and ... | check |
| CVE-2026-43629 | llama.cpp builds b4882 through b9058 contain a heap buffer overflow vu ... | check |
| CVE-2026-43631 | llama.cpp builds b7492 through the latest b9060 contains a use-after-f ... | check |
| CVE-2026-43632 | llama.cpp builds b7492 through the latest b9060 contains a use-after-f ... | check |
| CVE-2026-43829 | Full details and mitigation steps are currently restricted and will be ... | check |
| CVE-2026-43830 | Full details and mitigation steps are currently restricted and will be ... | check |
| CVE-2026-43831 | Full details and mitigation steps are currently restricted and will be ... | check |
| CVE-2026-43832 | Full details and mitigation steps are currently restricted and will be ... | check |
| CVE-2026-43833 | Full details and mitigation steps are currently restricted and will be ... | check |
| CVE-2026-44933 | `PluginScript` attempts to `chroot` the plugin to the `repoManagerRoot ... | check |
| CVE-2026-45388 | In OCaml-TLS before 2.1.0, the client implementation does insufficient ... | check |
| CVE-2026-45389 | In OCaml-TLS before 2.1.0, the server implementation does insufficient ... | check |
| CVE-2026-45390 | In OCaml-tar before 3.4.0, a crafted archive with ../ path segments in ... | check |
| CVE-2026-46696 | October System provides the system module for October Content Manageme ... | check |
| CVE-2026-46727 | An issue was discovered in Ruby 4 before 4.0.5. A race condition leadi ... | check |
| CVE-2026-47094 | SIMAC MyPHR 1.1 contains an insecure direct object reference (IDOR) vu ... | check |
| CVE-2026-47253 | Anyquery is an SQL query engine built on top of SQLite. Prior to 0.4.5 ... | check |
| CVE-2026-47875 | Applications that deserialize execution contexts with Jackson2Executio ... | check |
| CVE-2026-47878 | DefaultExecutionContextSerializer, used by default in Spring Batch's J ... | check |
| CVE-2026-47881 | Spring Batch's FlatFileItemReader supports files where a single logica ... | check |
| CVE-2026-48809 | python-engineio is a Python implementation of the Engine.IO realtime c ... | checking upstream commit fixing issue, confusing infomation advisory claims both 4.13.2 and 4.13.5 to fix issue |
| CVE-2026-49250 | Conform, a type-safe form validation library, allows the parsing of ne ... | check |
| CVE-2026-49400 | October System provides the system module for October Content Manageme ... | check |
| CVE-2026-50006 | Anyquery is an SQL query engine built on top of SQLite. Prior to 0.4.5 ... | check |
| CVE-2026-50157 | Auth0 Symfony is a Symfony SDK for Auth0 Authentication and Management ... | check |
| CVE-2026-50270 | dd-trace-java is a Datadog APM client for Java. Prior to 1.62.0, W3C b ... | check |
| CVE-2026-50276 | dd-trace-rb is Datadog's client library for Ruby. Prior to 2.32.0, W3C ... | check |
| CVE-2026-51133 | Cross Site Scripting vulnerability in za-internet GmbH C-MOR Video Sur ... | check |
| CVE-2026-51134 | The C-MOR Video Surveillance web interface (up to version 6.0104) is v ... | check |
| CVE-2026-51400 | An issue in Vim Project v9.2.0389 and earlier allows a local attacker ... | check, possibly not reported upstream, only reporter reference in github gist |
| CVE-2026-51401 | An issue in Vim Project v9.2.0389 and earlier allows a local attacker ... | check, possibly not reported upstream, only reporter reference in github gist |
| CVE-2026-51990 | An issue in Sogou Sogou Input Method < 16.3.0.3498 (fixed in 16.3.0.34 ... | check |
| CVE-2026-53496 | ExifReader is a JavaScript Exif information parser. Prior to 4.40.1, E ... | check |
| CVE-2026-53708 | ContextForge is an AI gateway, registry, and proxy that provides centr ... | check |
| CVE-2026-53752 | docx4j is an open source Java library for creating, editing, and savin ... | check |
| CVE-2026-54087 | EasyAdmin is a fast and modern admin generator for Symfony application ... | check |
| CVE-2026-54155 | node-opcua is an OPC UA implementation for TypeScript and Node.js. Pri ... | check |
| CVE-2026-54156 | node-opcua is an OPC UA implementation for TypeScript and Node.js. Pri ... | check |
| CVE-2026-54246 | Skipper is an HTTP router and reverse proxy for service composition. P ... | check |
| CVE-2026-54247 | Skipper is an HTTP router and reverse proxy for service composition. P ... | check |
| CVE-2026-54333 | UEFI Firmware Parser parses BIOS, Intel ME, and UEFI firmware structur ... | check |
| CVE-2026-54334 | UEFI Firmware Parser parses BIOS, Intel ME, and UEFI firmware structur ... | check |
| CVE-2026-54337 | Fireshare facilitates self-hosted media and link sharing. Prior to ver ... | check |
| CVE-2026-54447 | garminconnect is a Python 3 API wrapper for Garmin Connect that retrie ... | check |
| CVE-2026-54452 | safeurl is a server-side request forgery protection library. Prior to ... | check |
| CVE-2026-54529 | SQLAdmin is a flexible Admin interface for SQLAlchemy models. Prior to ... | check |
| CVE-2026-54541 | Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol ba ... | check |
| CVE-2026-54542 | Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol ba ... | check |
| CVE-2026-54544 | Fireshare facilitates self-hosted media and link sharing. Prior to ver ... | check |
| CVE-2026-54559 | PocketSphinx is a small speech recognizer. Prior to 5.1.1, the trie la ... | check |
| CVE-2026-54567 | Flask-Reuploaded provides file uploads for Flask. From 1.5.0 until 1.6 ... | check |
| CVE-2026-54628 | Anyquery is an SQL query engine built on top of SQLite. Prior to 0.4.5 ... | check |
| CVE-2026-54629 | Anyquery is an SQL query engine built on top of SQLite. Prior to 0.4.5 ... | check |
| CVE-2026-54632 | SIPSorcery is a WebRTC, SIP, and VoIP library for C# and .NET. Prior t ... | check |
| CVE-2026-54723 | devpi is a Python package index staging server and packaging, testing, ... | check |
| CVE-2026-55072 | Pimcore is an Open Source Data & Experience Management Platform. Prior ... | check |
| CVE-2026-55091 | flat-to-nested converts a hierarchy from a flat representation to a ne ... | check |
| CVE-2026-55093 | Tract is a tiny, no-nonsense, self-contained TensorFlow and ONNX infer ... | check |
| CVE-2026-55102 | hashi-vault-js is a Node.js module for interacting with the HashiCorp ... | check |
| CVE-2026-55209 | resdata is software for reading and writing result files from the Ecli ... | check |
| CVE-2026-55223 | c3p0 is a JDBC Connection pooling library. In versions prior to 0.14.0 ... | check if that is an issue with the packaged version |
| CVE-2026-55663 | mediasoup is a WebRTC video conferencing system. From version 3.20.0 u ... | check |
| CVE-2026-56684 | Valkey is a distributed key-value database. Prior to 7.2.14, 8.0.10, 8 ... | check redis and redict |
| CVE-2026-56816 | Netty is a network application framework for development of protocol s ... | check, potentially only in 4.2.y series |
| CVE-2026-56818 | Netty is an asynchronous, event-driven network application framework. ... | check missing upstream GHSA |
| CVE-2026-57862 | Kanboard 1.2.52 and prior contains a server-side request forgery vulne ... | check upstream report |
| CVE-2026-59739 | Information disclosure via SetWatches reconnect replay in Apache ZooKe ... | check |
| CVE-2026-59969 | Apache ZooKeeper quorum TLS fails to enforce peer hostname verificatio ... | check |
| CVE-2026-59974 | Stanza is a Stanford NLP Python library for tokenization, sentence seg ... | check |
| CVE-2026-61544 | libp2p-rust is the official Rust language implementation of the libp2p ... | check |
| CVE-2026-61554 | emp3r0r is a C2 designed by Linux users for Linux environments. Prior ... | check |
| CVE-2026-61709 | OpenFGA is an authorization and permission engine built for developers ... | check |
| CVE-2026-61711 | BuildKit is a toolkit for converting source code to build artifacts in ... | check security impact on docker.io |
| CVE-2026-61712 | BuildKit is a toolkit for converting source code to build artifacts in ... | check potential security impact on docker.io |
| CVE-2026-63126 | Wire provides gRPC and protocol buffers for Android, Kotlin, Swift, an ... | check |
| CVE-2026-63127 | RMCP is an official Rust SDK for the Model Context Protocol. Prior to ... | check |
| CVE-2026-63128 | RMCP is an official Rust SDK for the Model Context Protocol. Prior to ... | check |
| CVE-2026-63639 | Valkey is a distributed key-value database. Prior to 7.2.14, 8.0.10, 8 ... | check redis and redict |
| CVE-2026-63671 | MDC is a tool to take regular Markdown and write documents interacting ... | check |
| CVE-2026-64611 | A flaw was found in libcupsfilters. The cfIEEE1284NormalizeMakeModel() ... | check use in embedded cups, cups-filters |
| CVE-2026-66372 | The affected products use insufficiently random values, which allows w ... | check |
| CVE-2026-66887 | The affected products are missing authorization on state-changing CGIs ... | check |
| CVE-2026-66890 | The affected products use hard-coded credentials, which could allow re ... | check |
| CVE-2026-68006 | An issue in Puma v.5.0.0 and before v.8.0.3 allows an attacker to exec ... | check, unclear if https://github.com/czx1111/cve/issues/1 properly reported upstream |
| CVE-2026-68070 | The affected products are missing authentication for a critical functi ... | check |
| CVE-2026-68491 | An insufficient check allowed for the overwrite of arbitrary files via ... | check |
| CVE-2026-68536 | Server-Side Request Forgery / Local File Inclusion in Apache MyFace Co ... | check |
| CVE-2026-68904 | node-opcua is an OPC UA implementation for TypeScript and Node.js. Fro ... | check |
| CVE-2026-68950 | The affected products use hard-coded credentials, which could allow an ... | check |
| CVE-2026-68953 | The affected products are vulnerable to an authentication bypass that ... | check |
| CVE-2026-69200 | node-opcua is an OPC UA implementation for TypeScript and Node.js. Pri ... | check |
| CVE-2026-70755 | Vulnerability in the Oracle Web Applications Desktop Integrator produc ... | check |
| CVE-2026-71054 | Vulnerability in Oracle Java SE (component: 2D). Supported versions t ... | check |
| CVE-2026-71219 | A stack overflow vulnerability was found in gfs2-utils. The hash table ... | check upstream details |
| CVE-2026-71220 | A stack out-of-bounds write vulnerability was found in gfs2-utils. In ... | check upstream details |
| CVE-2026-71221 | A stack out-of-bounds write vulnerability was found in gfs2-utils. In ... | check upstream details |
| CVE-2026-71222 | A heap out-of-bounds read vulnerability was found in gfs2-utils. The e ... | check upstream details |
| CVE-2026-71224 | A stack overflow vulnerability was found in gfs2-utils. The metadata w ... | check upstream details |
| CVE-2026-71261 | dr_libs dr_wav.h (all versions through current master) contains an int ... | check if embedded copy has security impact in roc-toolkit, qtads, qt6-multimedia, octave-ltfat, raylib, dosbox-x, mlpack and faudio |
| CVE-2026-71266 | tinyobjloader-c's tinyobj_parse_and_index_mtl_file (tinyobj_loader_c.h ... | check |
| CVE-2026-71287 | Cacti's sanitize_sql_column (lib/functions.php) sanitizes user-supplie ... | check, assigned from "Turan Security" CNA without further detailed references |
| CVE-2026-71437 | Mermaid is a JavaScript tool that uses Markdown-inspired text to creat ... | check introducing commit for further assessment |
| CVE-2026-71439 | Mermaid is a JavaScript tool that uses Markdown-inspired text to creat ... | check introducing commit, might then be only 11.6.0 and above. |
| CVE-2026-72556 | A remote code execution vulnerability in ZoneMinder 1.39.17 allows any ... | check, another CVE assigned by "Turan Security" CNA without providing details |
| CVE-2026-73807 | The mySCADA myPRO Manager command API does not properly enforce authen ... | check |
| CVE-2026-73961 | Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middle ... | check |
| CVE-2026-75516 | The RabbitMQ Java client library allows Java and JVM-based application ... | check |
| CVE-2026-75593 | BuildKit is a toolkit for converting source code to build artifacts in ... | check security impact on docker.io |
| CVE-2026-76151 | Out-of-bounds read (buffer over-read) in the HTTP Cache-Control respon ... | check |
| CVE-2026-76186 | Apache Airflow Keycloak provider: from Airflow 3.3 the Keycloak auth m ... | check |
| CVE-2026-76187 | Apache Airflow Keycloak provider: the unauthenticated token endpoint a ... | check |
| CVE-2026-76420 | A vulnerability in the internal configuration of the Apache JServ Prot ... | check |
| CVE-2026-76796 | The LoadImageAsPngBase64 endpoint of the Newell Brands DYMO Connect De ... | check |
| CVE-2026-76820 | OpenCTI is an open source platform for managing cyber threat intellige ... | check |
| CVE-2026-76821 | OpenCTI is an open source platform for managing cyber threat intellige ... | check |
| CVE-2026-76825 | RestrictedPython is a tool that helps define a subset of the Python la ... | check |
| CVE-2026-76852 | Netcore NR268 firmware version 1.7.121109 has an improper integrity ve ... | check |
| CVE-2026-76853 | Netcore NR268 firmware version 1.7.121109 contains a security check by ... | check |
| CVE-2026-76854 | Netcore NR255-V version 1.5.130703 contains a sensitive information di ... | check |
| CVE-2026-76855 | Netcore NR255-V version 1.5.130703 contains a sensitive information di ... | check |
| CVE-2026-76856 | Netcore NR255-V firmware version 1.5.130703 contains a cross-site requ ... | check |
| CVE-2026-76857 | Netcore NR255-V firmware version 1.5.130703 contains a sensitive infor ... | check |
| CVE-2026-76858 | Netcore NR255-V version 1.5.130703 contains a stored cross-site script ... | check |
| CVE-2026-76859 | Netcore NR255-V version 1.5.130703 contains a sensitive information di ... | check |
| CVE-2026-76860 | Netcore NR255-V version 1.5.130703 contains a stack-based buffer overf ... | check |
| CVE-2026-76861 | Netcore NR255-V version 1.5.130703 contains a stack-based buffer overf ... | check |
| CVE-2026-76862 | Netcore NR255-V version 1.5.130703 contains an os command argument inj ... | check |
| CVE-2026-76863 | Netcore NR255-V version 1.5.130703 contains a sensitive information di ... | check |
| CVE-2026-76864 | NR255-V version 1.5.130703 fails to sanitize QoS rule names before the ... | check |
| CVE-2026-76865 | Netcore NR255-V version 1.5.130703 contains a null pointer dereference ... | check |
| CVE-2026-76866 | Netcore NR255-V firmware version 1.5.130703 builds root-run command li ... | check |
| CVE-2026-76867 | Netcore NR255-V firmware version 1.5.130703 contains a stored cross-si ... | check |
| CVE-2026-76868 | Netcore NR255-V version 1.5.130703 contains a null pointer dereference ... | check |
| CVE-2026-76869 | Netcore NR255-V version 1.5.130703 contains a stack-based buffer overf ... | check |
| CVE-2026-76870 | Netcore NR255-V version 1.5.130703 contains an out-of-bounds read vuln ... | check |
| CVE-2026-76871 | Netcore NR255-V version 1.5.130703 contains a sensitive information di ... | check |
| CVE-2026-76872 | Netcore NR255-V version 1.5.130703 contains a stored cross-site script ... | check |
| CVE-2026-76873 | Netcore NR255-V version 1.5.130703 contains a stored cross-site script ... | check |
| CVE-2026-76925 | A flaw was found in Flatpak. A Time-of-check to time-of-use (TOCTOU) r ... | check, CNA contacted for getting more information |
| CVE-2026-77360 | oRPC is an tool that helps build APIs that are end-to-end type-safe an ... | check |
| CVE-2026-77401 | Zope AccessControl provides a general security framework for use in Zo ... | check |
| CVE-2026-77403 | RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, Connec ... | check |
| CVE-2026-77404 | RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, URI.St ... | check |
| CVE-2026-77405 | RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, tlsCon ... | check |
| CVE-2026-77406 | RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, Channe ... | check |
| CVE-2026-77407 | RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, PlainA ... | check |
| CVE-2026-77408 | RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, the wr ... | check |
| CVE-2026-77409 | RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, Channe ... | check |
| CVE-2026-77410 | RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, Channe ... | check |
| CVE-2026-77411 | RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, readLo ... | check |
| CVE-2026-77412 | RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, readFi ... | check |
| CVE-2026-78178 | A vulnerability was determined in jQWidgets up to 24.0.1. This affects ... | check |
| CVE-2026-78225 | A hardcoded cryptographic server key vulnerability exists in the deplo ... | check |
| CVE-2026-78299 | In Eclipse Embedded CDT versions 6.0 to 6.7 if the CMSIS-Pack archive ... | check |
| CVE-2026-79298 | An issue in Howyar Technologies Inc SysReturn Versions prior to 11.3.0 ... | check |
| CVE-2026-79993 | The `deleteContainer` opcode (0x14/20) is processed without verifying ... | check |
| CVE-2026-79994 | The guest-to-host Unix-domain socket relay in Docker Sandboxes validat ... | check |
| CVE-2026-81176 | Svelte devalue is a JavaScript library that serializes values into str ... | check |
| CVE-2026-81326 | QND uses a hard-coded cryptographic key, which may allow a local attac ... | check |
| CVE-2026-81855 | A hardcoded cryptographic client authentication key vulnerability exis ... | check |
| CVE-2026-81875 | HAPI FHIR is a complete implementation of the HL7 FHIR standard for he ... | check |
| CVE-2026-81876 | HAPI FHIR is a complete implementation of the HL7 FHIR standard for he ... | check |
| CVE-2026-82399 | CoreDNS is a DNS server written in Go. Prior to 1.14.7, the DNS-over-H ... | check |
| CVE-2026-82410 | Pocketbase is an open source web backend written in go. Prior to 0.22. ... | check |
| CVE-2026-82567 | The myPRO Manager notification gateway exposes an unauthenticated HTTP ... | check |
| CVE-2026-82631 | A security flaw has been discovered in valkey-io valkey 9.1.0. The aff ... | check resis and restic |
| CVE-2026-82677 | A vulnerability was determined in valkey-io valkey 9.1.0. Impacted is ... | check redis, restic? |
| CVE-2026-82964 | Improper preservation of permissions in the Avast sandbox minifilter d ... | check |
| CVE-2026-82994 | Vulnerability in the Oracle Platform Security for Java product of Orac ... | check |
| CVE-2026-82995 | Vulnerability in the Oracle Platform Security for Java product of Orac ... | check |
| CVE-2026-82996 | Vulnerability in the Oracle Platform Security for Java product of Orac ... | check |
| CVE-2026-83011 | Vulnerability in the Oracle Platform Security for Java product of Orac ... | check |
| CVE-2026-83020 | Vulnerability in the Oracle Platform Security for Java product of Orac ... | check |
| CVE-2026-83044 | Vulnerability in the Oracle XML Gateway product of Oracle E-Business S ... | check |
| CVE-2026-83054 | Vulnerability in the Oracle Internet Directory product of Oracle Fusio ... | check |
| CVE-2026-83055 | Vulnerability in the Oracle Internet Directory product of Oracle Fusio ... | check |
| CVE-2026-83056 | Vulnerability in the Oracle Internet Directory product of Oracle Fusio ... | check |
| CVE-2026-83057 | Vulnerability in the Oracle Internet Directory product of Oracle Fusio ... | check |
| CVE-2026-83058 | Vulnerability in the Oracle Internet Directory product of Oracle Fusio ... | check |
| CVE-2026-83059 | Vulnerability in the Oracle Internet Directory product of Oracle Fusio ... | check |
| CVE-2026-83060 | Vulnerability in the Oracle Internet Directory product of Oracle Fusio ... | check |
| CVE-2026-83061 | Vulnerability in the Oracle Internet Directory product of Oracle Fusio ... | check |
| CVE-2026-83062 | Vulnerability in the Oracle Internet Directory product of Oracle Fusio ... | check |
| CVE-2026-83063 | Vulnerability in the Oracle Internet Directory product of Oracle Fusio ... | check |
| CVE-2026-83066 | Vulnerability in the Oracle Internet Directory product of Oracle Fusio ... | check |
| CVE-2026-83067 | Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middle ... | check |
| CVE-2026-83068 | Vulnerability in the Oracle Enterprise Manager for Oracle Database pro ... | check |
| CVE-2026-83069 | Vulnerability in the Oracle Fusion Middleware Control product of Oracl ... | check |
| CVE-2026-83070 | Vulnerability in the PeopleSoft Enterprise PRTL Interaction Hub produc ... | check |
| CVE-2026-83080 | Vulnerability in the Oracle Banking Branch product of Oracle Financial ... | check |
| CVE-2026-83081 | Vulnerability in the Oracle Banking Corporate Lending product of Oracl ... | check |
| CVE-2026-83089 | Vulnerability in the Oracle Alert product of Oracle E-Business Suite ( ... | check |
| CVE-2026-83091 | Vulnerability in the Oracle Field Service product of Oracle E-Business ... | check |
| CVE-2026-83092 | Vulnerability in the Oracle Field Service product of Oracle E-Business ... | check |
| CVE-2026-83093 | Vulnerability in the Oracle Forms product of Oracle Fusion Middleware ... | check |
| CVE-2026-83094 | Vulnerability in the Oracle Forms product of Oracle Fusion Middleware ... | check |
| CVE-2026-83095 | Vulnerability in the Oracle Forms product of Oracle Fusion Middleware ... | check |
| CVE-2026-83096 | Vulnerability in the Oracle Forms product of Oracle Fusion Middleware ... | check |
| CVE-2026-83097 | Vulnerability in the Oracle Forms product of Oracle Fusion Middleware ... | check |
| CVE-2026-83098 | Vulnerability in the Oracle Forms product of Oracle Fusion Middleware ... | check |
| CVE-2026-83099 | Vulnerability in the Oracle Forms product of Oracle Fusion Middleware ... | check |
| CVE-2026-83100 | Vulnerability in the Oracle Forms product of Oracle Fusion Middleware ... | check |
| CVE-2026-83101 | Vulnerability in the Oracle Forms product of Oracle Fusion Middleware ... | check |
| CVE-2026-83102 | Vulnerability in the Oracle Forms product of Oracle Fusion Middleware ... | check |
| CVE-2026-83103 | Vulnerability in the Oracle Forms product of Oracle Fusion Middleware ... | check |
| CVE-2026-83104 | Vulnerability in the Oracle Forms product of Oracle Fusion Middleware ... | check |
| CVE-2026-83105 | Vulnerability in the Oracle Forms product of Oracle Fusion Middleware ... | check |
| CVE-2026-83106 | Vulnerability in the Oracle Forms product of Oracle Fusion Middleware ... | check |
| CVE-2026-83107 | Vulnerability in the Oracle Forms product of Oracle Fusion Middleware ... | check |
| CVE-2026-83108 | Vulnerability in the Oracle Forms product of Oracle Fusion Middleware ... | check |
| CVE-2026-83109 | Vulnerability in the Oracle Forms product of Oracle Fusion Middleware ... | check |
| CVE-2026-83111 | Vulnerability in the Oracle Partner Management product of Oracle E-Bus ... | check |
| CVE-2026-83117 | Vulnerability in the Applications DBA product of Oracle E-Business Sui ... | check |
| CVE-2026-83118 | Vulnerability in the Applications DBA product of Oracle E-Business Sui ... | check |
| CVE-2026-83120 | Vulnerability in the Oracle Alert product of Oracle E-Business Suite ( ... | check |
| CVE-2026-83122 | Vulnerability in the Oracle Report Manager product of Oracle E-Busines ... | check |
| CVE-2026-83123 | Vulnerability in the Oracle Report Manager product of Oracle E-Busines ... | check |
| CVE-2026-83124 | Vulnerability in the Oracle Sales Online product of Oracle E-Business ... | check |
| CVE-2026-83125 | Vulnerability in the Oracle Report Manager product of Oracle E-Busines ... | check |
| CVE-2026-83126 | Vulnerability in the Oracle Sales Online product of Oracle E-Business ... | check |
| CVE-2026-83127 | Vulnerability in the Oracle Sales Offline product of Oracle E-Business ... | check |
| CVE-2026-83128 | Vulnerability in the Oracle Sales Offline product of Oracle E-Business ... | check |
| CVE-2026-83129 | Vulnerability in the Oracle Sales product of Oracle E-Business Suite ( ... | check |
| CVE-2026-83130 | Vulnerability in the Oracle Site Hub product of Oracle E-Business Suit ... | check |
| CVE-2026-83131 | Vulnerability in the Oracle Web Applications Desktop Integrator produc ... | check |
| CVE-2026-83140 | Vulnerability in the Oracle Field Service product of Oracle E-Business ... | check |
| CVE-2026-83141 | Vulnerability in the Oracle Field Service product of Oracle E-Business ... | check |
| CVE-2026-83142 | Vulnerability in the Oracle Proposals product of Oracle E-Business Sui ... | check |
| CVE-2026-83143 | Vulnerability in the Siebel Apps - Life Sciences product of Oracle Sie ... | check |
| CVE-2026-83144 | Vulnerability in the Siebel Apps - Customer Order Management product o ... | check |
| CVE-2026-83145 | Vulnerability in the Siebel Apps - Customer Order Management product o ... | check |
| CVE-2026-83147 | Vulnerability in the PeopleSoft Enterprise FIN Inventory Brazil produc ... | check |
| CVE-2026-83152 | Vulnerability in the Oracle Project Intelligence product of Oracle E-B ... | check |
| CVE-2026-83159 | Vulnerability in the Applications DBA product of Oracle E-Business Sui ... | check |
| CVE-2026-83161 | Vulnerability in the Oracle Project Intelligence product of Oracle E-B ... | check |
| CVE-2026-83164 | Vulnerability in the Oracle Customer Interaction History product of Or ... | check |
| CVE-2026-83165 | Vulnerability in the Oracle Customer Interaction History product of Or ... | check |
| CVE-2026-83166 | Vulnerability in the Oracle Customer Interaction History product of Or ... | check |
| CVE-2026-83169 | Vulnerability in the Oracle One-to-One Fulfillment product of Oracle E ... | check |
| CVE-2026-83170 | Vulnerability in the Oracle One-to-One Fulfillment product of Oracle E ... | check |
| CVE-2026-83171 | Vulnerability in the Oracle One-to-One Fulfillment product of Oracle E ... | check |
| CVE-2026-83172 | Vulnerability in the Oracle Sales Online product of Oracle E-Business ... | check |
| CVE-2026-83173 | Vulnerability in the Oracle One-to-One Fulfillment product of Oracle E ... | check |
| CVE-2026-83177 | Vulnerability in the Oracle One-to-One Fulfillment product of Oracle E ... | check |
| CVE-2026-83179 | Vulnerability in the Oracle Common Applications Calendar product of Or ... | check |
| CVE-2026-83181 | Vulnerability in the Siebel CRM Development product of Oracle Siebel C ... | check |
| CVE-2026-83182 | Vulnerability in the Siebel CRM Development product of Oracle Siebel C ... | check |
| CVE-2026-83186 | Vulnerability in the Oracle Common Applications Calendar product of Or ... | check |
| CVE-2026-83187 | Vulnerability in the Oracle Common Applications Calendar product of Or ... | check |
| CVE-2026-83188 | Vulnerability in the Oracle Depot Repair product of Oracle E-Business ... | check |
| CVE-2026-83193 | Vulnerability in the Siebel Apps - Life Sciences product of Oracle Sie ... | check |
| CVE-2026-83194 | Vulnerability in the Oracle Depot Repair product of Oracle E-Business ... | check |
| CVE-2026-83197 | Vulnerability in the Siebel Apps - Financial Services product of Oracl ... | check |
| CVE-2026-83198 | Vulnerability in the Oracle Field Service product of Oracle E-Business ... | check |
| CVE-2026-83200 | Vulnerability in the Oracle Process Manufacturing Intelligence product ... | check |
| CVE-2026-83204 | Vulnerability in the Oracle Sourcing product of Oracle E-Business Suit ... | check |
| CVE-2026-83206 | Vulnerability in the Oracle Banking Corporate Lending Process Manageme ... | check |
| CVE-2026-83207 | Vulnerability in the Siebel CRM Development product of Oracle Siebel C ... | check |
| CVE-2026-83209 | Vulnerability in the Siebel CRM Development product of Oracle Siebel C ... | check |
| CVE-2026-83266 | Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middle ... | check |
| CVE-2026-83300 | Vulnerability in the Oracle XML Gateway product of Oracle E-Business S ... | check |
| CVE-2026-83306 | Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middle ... | check |
| CVE-2026-83337 | Vulnerability in the Oracle Middleware Common Libraries and Tools prod ... | check |
| CVE-2026-83342 | Vulnerability in the Oracle Utilities Network Management System produc ... | check |
| CVE-2026-83343 | Vulnerability in the Oracle Utilities Network Management System produc ... | check |
| CVE-2026-83345 | Vulnerability in the Oracle XML Gateway product of Oracle E-Business S ... | check |
| CVE-2026-83346 | Vulnerability in the Oracle Fusion Middleware Control product of Oracl ... | check |
| CVE-2026-83352 | Vulnerability in the Oracle XML Gateway product of Oracle E-Business S ... | check |
| CVE-2026-83355 | Vulnerability in the Oracle Enterprise Manager for Fusion Middleware p ... | check |
| CVE-2026-83356 | Vulnerability in the Enterprise Command Center Framework product of Or ... | check |
| CVE-2026-83357 | Vulnerability in the Oracle GraalVM for JDK, Oracle GraalVM product of ... | check |
| CVE-2026-83368 | Vulnerability in the Oracle GraalVM for JDK, Oracle GraalVM Enterprise ... | check |
| CVE-2026-83408 | Vulnerability in the Oracle GraalVM for JDK, Oracle GraalVM product of ... | check |
| CVE-2026-83417 | Vulnerability in the Oracle Communications Cloud Native Core Security ... | check |
| CVE-2026-83418 | Vulnerability in the Oracle Communications Cloud Native Core Security ... | check |
| CVE-2026-83419 | Vulnerability in the Oracle Communications Cloud Native Core Security ... | check |
| CVE-2026-83420 | Vulnerability in the PeopleSoft Enterprise FIN Engineering Brazil prod ... | check |
| CVE-2026-83423 | Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middle ... | check |
| CVE-2026-83424 | Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middle ... | check |
| CVE-2026-83428 | Vulnerability in the Oracle Demand Signal Repository product of Oracle ... | check |
| CVE-2026-83429 | Vulnerability in the Oracle Demand Signal Repository product of Oracle ... | check |
| CVE-2026-83430 | Vulnerability in the Oracle Product Workbench product of Oracle E-Busi ... | check |
| CVE-2026-83431 | Vulnerability in the Oracle Product Workbench product of Oracle E-Busi ... | check |
| CVE-2026-83432 | Vulnerability in the Oracle Depot Repair product of Oracle E-Business ... | check |
| CVE-2026-83433 | Vulnerability in the Oracle Depot Repair product of Oracle E-Business ... | check |
| CVE-2026-83434 | Vulnerability in the Oracle Product Workbench product of Oracle E-Busi ... | check |
| CVE-2026-83435 | Vulnerability in the Oracle Bills of Material product of Oracle E-Busi ... | check |
| CVE-2026-83436 | Vulnerability in the Oracle Depot Repair product of Oracle E-Business ... | check |
| CVE-2026-83437 | Vulnerability in the Oracle Engineering product of Oracle E-Business S ... | check |
| CVE-2026-83438 | Vulnerability in the Oracle Engineering product of Oracle E-Business S ... | check |
| CVE-2026-83443 | Vulnerability in the Oracle Assets product of Oracle E-Business Suite ... | check |
| CVE-2026-83446 | Vulnerability in the Oracle Financials Common Modules product of Oracl ... | check |
| CVE-2026-83447 | Vulnerability in the Oracle Bills of Material product of Oracle E-Busi ... | check |
| CVE-2026-83448 | Vulnerability in the Oracle Bills of Material product of Oracle E-Busi ... | check |
| CVE-2026-83449 | Vulnerability in the Oracle Bills of Material product of Oracle E-Busi ... | check |
| CVE-2026-83450 | Vulnerability in the Oracle Bills of Material product of Oracle E-Busi ... | check |
| CVE-2026-83451 | Vulnerability in the Oracle Product Workbench product of Oracle E-Busi ... | check |
| CVE-2026-83452 | Vulnerability in the Oracle Document Management and Collaboration prod ... | check |
| CVE-2026-83453 | Vulnerability in the Oracle Document Management and Collaboration prod ... | check |
| CVE-2026-83454 | Vulnerability in the Oracle Document Management and Collaboration prod ... | check |
| CVE-2026-83455 | Vulnerability in the Oracle Demand Signal Repository product of Oracle ... | check |
| CVE-2026-83456 | Vulnerability in the Oracle Demand Signal Repository product of Oracle ... | check |
| CVE-2026-83457 | Vulnerability in the Oracle Demand Signal Repository product of Oracle ... | check |
| CVE-2026-83461 | Vulnerability in the Oracle Mobile Application Server product of Oracl ... | check |
| CVE-2026-83462 | Vulnerability in the Oracle Mobile Application Server product of Oracl ... | check |
| CVE-2026-83463 | Vulnerability in the Oracle Mobile Application Server product of Oracl ... | check |
| CVE-2026-83464 | Vulnerability in the Oracle Mobile Application Server product of Oracl ... | check |
| CVE-2026-83465 | Vulnerability in the Oracle Mobile Application Server product of Oracl ... | check |
| CVE-2026-83477 | Vulnerability in the Oracle Work in Process product of Oracle E-Busine ... | check |
| CVE-2026-83479 | Vulnerability in the Oracle Contracts product of Oracle E-Business Sui ... | check |
| CVE-2026-83481 | Vulnerability in the Oracle Contracts product of Oracle E-Business Sui ... | check |
| CVE-2026-83482 | Vulnerability in the Oracle Contracts product of Oracle E-Business Sui ... | check |
| CVE-2026-83483 | Vulnerability in the Oracle Advanced Benefits product of Oracle E-Busi ... | check |
| CVE-2026-83484 | Vulnerability in the Oracle US Federal Human Resources product of Orac ... | check |
| CVE-2026-83489 | Vulnerability in the Oracle Banking Origination product of Oracle Fina ... | check |
| CVE-2026-84233 | A flaw was found in rpm. A local attacker could supply a specially cra ... | check upstream details |
| CVE-2026-84408 | QND contains an improper access control vulnerability in a named pipe, ... | check |
| CVE-2026-84439 | When audit logging is enabled (zookeeper.audit.enable=true), an unauth ... | check |
| CVE-2026-84501 | An unauthenticated attacker can inject arbitrary fake log lines into A ... | check |
| CVE-2026-84858 | ScadaLTS 2.8.1-release-candidate build 0 is affected by anAuthenticate ... | check |
| CVE-2026-84859 | ScadaLTS 2.8.1-release-candidate build 0 is affected by anAuthenticate ... | check |
| CVE-2026-84860 | ScadaLTS 2.8.1-release-candidate build 0 is affected by anAuthorizatio ... | check |
| CVE-2026-84993 | MikroORM is a TypeScript ORM for Node.js based on Data Mapper, Unit of ... | check |
| CVE-2026-84997 | react/http is an event-driven, streaming HTTP client and server implem ... | check |
| CVE-2026-85104 | In Sooma 2GEN brain stimulator, an attacker within Bluetooth range can ... | check |
| CVE-2026-85150 | A NULL pointer dereference flaw was found in GStreamer's RTSP support ... | double-check, the MR is still not public, but advisory states fixed in 1.28.7 |
| CVE-2026-85628 | Transmission of the home Wi-Fi credentials without encryption during t ... | check |
| CVE-2026-85731 | oras-go is a Go library for managing OCI artifacts. Prior to 2.6.2, co ... | check |
| CVE-2026-85732 | oras-go is a Go library for managing OCI artifacts. Prior to 2.6.2, th ... | check |
| CVE-2026-85756 | SSH.NET is a Secure Shell (SSH) library for .NET. Prior to 2026.0.0, S ... | check |
| CVE-2026-86003 | CoreDNS is a DNS server written in Go. Prior to 1.14.7, the DNS-over-H ... | check |
| CVE-2026-86043 | Skipper is an HTTP router and reverse proxy for service composition. P ... | check |
| CVE-2026-86338 | Ash field_policies are documented to protect against filter-based info ... | check |
| CVE-2026-86443 | Cleartext storage of sensitive information in the DuoxMe application f ... | check |
| CVE-2026-86474 | The lack of TLS certificate validation when downloading firmware updat ... | check |
| CVE-2026-86585 | The lack of signature verification of firmware update packages in VEO ... | check |
| CVE-2026-86776 | KeePass versions 2.35 through 2.61.1 fail to validate KDBX header fiel ... | check upstream details |
| CVE-2026-86836 | In Eclipse Ankaios versions 0.1.0 through 1.0.2, the agent creates wor ... | check |
| CVE-2026-87020 | An integer overflow in a specified pitch and buffer-size computation l ... | check, might be a dupe of the existing issues addressed in 1.13, needs clarification |
| CVE-2026-87126 | Vulnerability in the Oracle Report Manager product of Oracle E-Busines ... | check |
| CVE-2026-87149 | Vulnerability in the Oracle Contract Lifecycle Management for Public S ... | check |
| CVE-2026-87150 | Vulnerability in the Oracle Bills of Material product of Oracle E-Busi ... | check |
| CVE-2026-87151 | Vulnerability in the Oracle Bills of Material product of Oracle E-Busi ... | check |
| CVE-2026-87152 | Vulnerability in the Oracle Installed Base product of Oracle E-Busines ... | check |
| CVE-2026-87159 | Vulnerability in the Oracle HRMS (India) product of Oracle E-Business ... | check |
| CVE-2026-87160 | Vulnerability in the Oracle HRMS (India) product of Oracle E-Business ... | check |
| CVE-2026-87161 | Vulnerability in the Oracle HRMS (India) product of Oracle E-Business ... | check |
| CVE-2026-87162 | Vulnerability in the Oracle Contract Lifecycle Management for Public S ... | check |
| CVE-2026-87164 | Vulnerability in the Oracle Banking Branch product of Oracle Financial ... | check |
| CVE-2026-87165 | Vulnerability in the Oracle Contract Lifecycle Management for Public S ... | check |
| CVE-2026-87169 | Vulnerability in the Oracle Contract Lifecycle Management for Public S ... | check |
| CVE-2026-87267 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualiza ... | check |
| CVE-2026-87268 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualiza ... | check |
| CVE-2026-87269 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualiza ... | check |
| CVE-2026-87270 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualiza ... | check |
| CVE-2026-87271 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualiza ... | check |
| CVE-2026-87272 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualiza ... | check |
| CVE-2026-87273 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualiza ... | check |
| CVE-2026-87274 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualiza ... | check |
| CVE-2026-87275 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualiza ... | check |
| CVE-2026-87276 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualiza ... | check |
| CVE-2026-87277 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualiza ... | check |
| CVE-2026-87278 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualiza ... | check |
| CVE-2026-87279 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualiza ... | check |
| CVE-2026-87280 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualiza ... | check |
| CVE-2026-87281 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualiza ... | check |
| CVE-2026-87282 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualiza ... | check |
| CVE-2026-87283 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualiza ... | check |
| CVE-2026-87284 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualiza ... | check |
| CVE-2026-87285 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualiza ... | check |
| CVE-2026-87286 | Vulnerability in the Oracle GraalVM product of Oracle Java SE (compone ... | check |
| CVE-2026-87287 | Vulnerability in the Oracle GraalVM product of Oracle Java SE (compone ... | check |
| CVE-2026-87288 | Vulnerability in the Oracle GraalVM product of Oracle Java SE (compone ... | check |
| CVE-2026-88064 | Backstage is an open framework for building developer portals. Prior t ... | check |
| CVE-2026-88065 | `tts-be` is a backend for a timetable selector that aims to help stude ... | check |
| CVE-2026-88255 | Improper Validation of Unsafe Equivalence in Input in ZenHive mpp allo ... | check |
| CVE-2026-88263 | XikeStor Layer3 switches miss authentication for downloading configura ... | check |
| CVE-2026-88593 | kkFileView 5.0.0 through 5.0.2 allows reflected XSS via the /onlinePre ... | check |
| CVE-2026-88742 | Bacularis 1.0.0 - 6.5.0 is vulnerable to Stored cross-site scripting ( ... | check |
| CVE-2026-88743 | Bacularis 4.7.0 - 6.5.0 is vulnerable to Stored cross-site scripting ( ... | check |
| CVE-2026-88817 | An authenticated, non-guest user of Curiosity Workspace could enroll t ... | check |
| CVE-2026-88819 | In Siglet current and past versions the refresh token handler do not e ... | check |
| CVE-2026-88922 | The go-getter library up to versions 1.8.8 and 2.2.3 is vulnerable to ... | check |
| CVE-2026-88976 | Plate is a rich-text editor with AI and shadcn/ui. Prior to 53.3.11, a ... | check |
| CVE-2026-89027 | miniOrange JWT Authentication for WP REST APIs plugin for WordPress be ... | check |
| CVE-2026-89040 | Tencent Mass Service Engine in Cluster (MSEC) allows a remote, unauthe ... | check |
| CVE-2026-89186 | Use of Cache Containing Sensitive Information in ZenHive mpp allows a ... | check |
| CVE-2026-89321 | Publishing limits the compressed size of a VSIX (ovsx.publishing.max-c ... | check |
| CVE-2026-90648 | wasm2c in WebAssembly wabt through 1.0.41 allows sandbox escape in som ... | check upstream details |
| CVE-2026-90999 | Sentry Seer is vulnerable to a multi-stage trust-boundary violation th ... | check |
| CVE-2026-91843 | A stack overflow during the unauthenticated login process may allow an ... | check |
| CVE-2026-91939 | Cotonti 1.0.0 Comments plugin passes the ci GET parameter to unseriali ... | check |
| CVE-2026-92081 | fastify is a fast and low-overhead web framework for Node.js. In versi ... | check |
| CVE-2026-92091 | A flaw was found in jwcrypto. The JWK.import_key() function validates ... | check |
| CVE-2026-92221 | A vulnerability was determined in gedelumbung HospitalManagement up to ... | check |
| CVE-2026-92234 | QloApps through 1.7.0 reflects unescaped child feature names into back ... | check |
| CVE-2026-92247 | A security vulnerability has been detected in synaptikcms synaptik-cms ... | check |
| CVE-2026-92255 | Netcore NR255-V version 1.5.130703 contains an out-of-bounds read vuln ... | check |
| CVE-2026-92256 | NR255-V version 1.5.130703 contains a sensitive information disclosure ... | check |
| CVE-2026-92257 | Netcore NR255-V version 1.5.130703 contains a stored cross-site script ... | check |
| CVE-2026-92298 | EspoCRM through 10.0.8 uses PHP's rand() function to generate tokens f ... | check |
| CVE-2026-92299 | @jitsi/electron-sdk before 10.0.5 exposes getDesktopSources() via cont ... | check |
| CVE-2026-92356 | A vulnerability was determined in a2ui-project a2ui 0.9/0.9.1. This is ... | check |
| CVE-2026-92357 | A vulnerability was identified in a2ui-project a2ui 0.8/0.9/1.0. Impac ... | check |
| CVE-2026-92359 | A security flaw has been discovered in ag-ui-protocol ag-ui 0.3.0. The ... | check |
| CVE-2026-92360 | A weakness has been identified in ag-ui-protocol ag-ui 1.0. The impact ... | check |
| CVE-2026-92361 | A security vulnerability has been detected in ag-ui-protocol ag-ui 1.0 ... | check |
| CVE-2026-92362 | A vulnerability was detected in ag-ui-protocol ag-ui 1.0. This impacts ... | check |
| CVE-2026-92363 | A flaw has been found in ag-ui-protocol ag-ui 1.0. Affected is an unkn ... | check |
| CVE-2026-92365 | A vulnerability was found in vllm-project vllm up to 0.29.0. Affected ... | check |
| CVE-2026-92401 | A vulnerability was identified in ChangeWeDer crm up to c07bd4c9714152 ... | check |
| CVE-2026-92402 | A security flaw has been discovered in ChangeWeDer crm up to c07bd4c97 ... | check |
| CVE-2026-92413 | A flaw has been found in Artifex MuPDF up to b6d17493700c621c0e7003698 ... | check |
| CVE-2026-92418 | A vulnerability was determined in ChangeWeDer crm up to c07bd4c9714152 ... | check |
| CVE-2026-92565 | Rallly before 4.15.0 contains an information disclosure vulnerability ... | check |
| CVE-2026-92566 | DataGear through 6.0.0 contains a server-side request forgery vulnerab ... | check |
| CVE-2026-92567 | TDuck survey form through version 5.0 contains an authorization bypass ... | check |
| CVE-2026-92568 | MLRun through 1.11.0 contains a server-side request forgery vulnerabil ... | check |
| CVE-2026-92569 | Hippo4j through 1.5.0 contains a server-side request forgery vulnerabi ... | check |
| CVE-2026-92570 | reNgine through 2.2.0 contains an authorization bypass vulnerability i ... | check |
| CVE-2026-92600 | Guns through 8.3.5 contains an information disclosure vulnerability in ... | check |
| CVE-2026-92601 | Guns through 8.3.5 contains an improper access control vulnerability i ... | check |
| CVE-2026-92615 | A flaw was found in flightctl. The configureRepoHTTPSClient() function ... | check |
| CVE-2026-92627 | A heap-use-after-free vulnerability exists in H5T__conv_f_f() in src/H ... | check |
| CVE-2026-92716 | Shuffle through 2.2.1 contains a cross-tenant privilege escalation vul ... | check |
| TEMP-1142597-FFA22A | GHSA-68ff-gq39-pqjm: relay: authentication bypass with the "plain" password hash algorithm | check, GHSA-68ff-gq39-pqjm claims >= 4.3.0 but potentially since v2.9-rc1 |