Bugs with TODO items

Hide "check" TODOs

BugDescriptionNote
CVE-2016-1584In all versions of Unity8 a running but not active application on a la ...check proper tracking update
CVE-2018-25246Wikipedia 12.0 contains a denial of service vulnerability that allows ...check
CVE-2018-25305librsvg2-bin 2.40.13 contains a buffer overflow vulnerability that all ...check
CVE-2018-25306PDFunite 0.41.0 contains a buffer overflow vulnerability that allows l ...check
CVE-2019-25485R 3.4.4 on Windows x64 contains a buffer overflow vulnerability in the ...check
CVE-2019-25683FileZilla 3.40.0 contains a denial of service vulnerability in the loc ...check
CVE-2022-4996A flaw has been found in mruby 3.1.0. Affected is the function udiv of ...check
CVE-2022-23538github.com/sylabs/scs-library-client is the Go client for the Singular ...check details, might as well affect golang-github-apptainer-container-library-client
CVE-2022-50942Incinga Web 2.8.2 contains a client-side cross-site scripting vulnerab ...check status upstream
CVE-2023-20511Release of an invalid pointer in the AMD kernel mode driver (KMD) coul ...check
CVE-2023-26044react/http is an event-driven, streaming HTTP client and server implem ...check, is embedded inicinga-php-thirdparty, icingaweb2-module-reactbundle possibly affected
CVE-2023-31308A malicious virtual function can invoke the certain command handlers i ...check
CVE-2023-47268In libslic3r/GCode/PostProcessor.cpp in Prusa PrusaSlicer through 2.6. ...check
CVE-2023-49316In Math/BinaryField.php in phpseclib 3 before 3.0.34, excessively larg ...check if affecting ldap-account-manager or unused path
CVE-2023-50251php-svg-lib is an SVG file parsing / rendering library. Prior to versi ...check, other packages are embedding the library: civicrm, icinga-php-thirdparty and icingaweb2 to be checked
CVE-2023-50252php-svg-lib is an SVG file parsing / rendering library. Prior to versi ...check, other packages are embedding the library: civicrm, icinga-php-thirdparty and icingaweb2 to be checked
CVE-2023-50262Dompdf is an HTML to PDF converter for PHP. When parsing SVG images Do ...check sources embedding php-dompdf if affected
CVE-2023-54356Kyverno versions 1.9.4 and earlier support insecure 3DES cipher suites ...check
CVE-2024-7708For requests that have a body, but reading the body may end up in read ...check
CVE-2024-14047A local vulnerability in the Winlogbeat Windows installer caused runti ...check
CVE-2024-22420JupyterLab is an extensible environment for interactive and reproducib ...check completeness, src:jupyter-notebook?
CVE-2024-22421JupyterLab is an extensible environment for interactive and reproducib ...check completeness, src:jupyter-notebook?
CVE-2024-47091Privilege escalation in the mk_mysql agent plugin on Windows in Checkm ...check
CVE-2024-54192An issue inTcpreplay v4.5.1 allows a local attacker to cause a denial ...check
CVE-2025-4382A flaw was found in systems utilizing LUKS-encrypted disks with GRUB c ...double check if vulnerability only considered present after grub_is_cli_disabled is introduced
CVE-2025-6499A vulnerability classified as problematic was found in vstakhov libucl ...check if impacts security wise rspamd, which embeds libucl and uses it a compile time
CVE-2025-8671A mismatch caused by client-triggered server-sent stream resets betwee ...check, some projects will assign own CVEs and should then be covered under that specific CVE instead
CVE-2025-8941A flaw was found in linux-pam. The pam_namespace module may improperly ...check likely RedHat specific incomplete fix for CVE-2025-6020, but asked to pinpoint incomplete fixes
CVE-2025-11010A vulnerability has been found in vstakhov libucl up to 0.9.2. Affecte ...check if impacts security wise rspamd, which embeds libucl and uses it a compile time
CVE-2025-11147Reflected cross-site scripting (XSS) in Apt-Cacher-NG v3.2.1. The vuln ...clarifying with reporter and Eduard Bloch on the issue.
CVE-2025-14575An Uncontrolled Search Path Element vulnerability in the OpenSSL TLS b ...check
CVE-2025-15569A flaw has been found in Artifex MuPDF up to 1.26.1 on Windows. The im ...check
CVE-2025-15613Kyverno before v1.13.4 is vulnerable to server-side request forgery (S ...check
CVE-2025-33221NVIDIA Display Driver for Windows and Linux contains a vulnerability i ...check
CVE-2025-58064CKEditor 5 is a modern JavaScript rich-text editor with an MVC archite ...check
CVE-2025-60796phpPgAdmin 7.13.0 and earlier contains multiple cross-site scripting ( ...check, possibly not reported upstream
CVE-2025-60797phpPgAdmin 7.13.0 and earlier contains a SQL injection vulnerability i ...check, possibly not reported upstream
CVE-2025-60798phpPgAdmin 7.13.0 and earlier contains a SQL injection vulnerability i ...check, possibly not reported upstream
CVE-2025-60799phpPgAdmin 7.13.0 and earlier contains an incorrect access control vul ...check, possibly not reported upstream
CVE-2025-61261A reflected cross-site scripting (XSS) vulnerability in CKeditor v46.1 ...check
CVE-2025-61982An arbitrary code execution vulnerability exists in the Code Stream di ...check upstream status
CVE-2025-63607TechStore 1.0 is vulnerable to Cross Site Scripting (XSS). In contact_ ...check
CVE-2025-63913An issue was discovered in OpenSBI 1.3 allowing attackers to cause a d ...check
CVE-2025-66578xmlseclibs is a library written in PHP for working with XML Encryption ...check
CVE-2025-67108eProsima Fast-DDS v3.3 was discovered to contain improper validation f ...check https://gist.github.com/lkloliver/81b5d5a8328d712dbfd497bf11dbe913, unclear if reported upstream
CVE-2025-69534Python-Markdown version 3.8 contain a vulnerability where malformed HT ...Asking whether it really needs a backport: https://bugs.debian.org/1131896
CVE-2025-69720The infocmp command-line tool in ncurses before 6.5-20251213 has a sta ...check upstream status
CVE-2025-69969A lack of authentication and authorization mechanisms in the Bluetooth ...check
CVE-2025-70887An issue in ralphje Signify before v.0.9.2 allows a remote attacker to ...check
CVE-2026-0708A flaw was found in libucl. A remote attacker could exploit this by pr ...check if impacts security wise rspamd, which embeds libucl and uses it a compile time
CVE-2026-1703When pip is installing and extracting a maliciously crafted wheel arch ...check as well pipenv
CVE-2026-4813A vulnerability in the Lutece Core XSL export management module up to ...check
CVE-2026-4833A weakness has been identified in Orc discount up to 3.0.1.2. This iss ...check libtext-markdown-discount-perl, ruby-rdiscount, cantor, embedding discount; check if security impact present
CVE-2026-5422A path traversal vulnerability exists in jupyter-server version 2.17.0 ...CNA contacted responsible for this CVE entry as this seems to be a duplicate of CVE-2026-35397
CVE-2026-5956Improper neutralization of special elements used in an SQL command ('S ...check
CVE-2026-6657A vulnerability in jupyter-server versions 1.12.0 through 2.17.0 allow ...CNA contacted responsible for this CVE entry as this seems to be a duplicate of CVE-2026-40110
CVE-2026-7701A security vulnerability has been detected in Telegram Desktop up to 6 ...check upstream reports
CVE-2026-7790Uncontrolled Resource Consumption vulnerability in ninenines cowlib (c ...check if embedded copy in rabbitmq-server is problematic
CVE-2026-8851SOGo versions 5.12.7 and prior contains a SQL injection vulnerability ...check correctness
CVE-2026-8863Multiple Microsoft-sigend UEFI SHIM bootloaders are vulnerable to Secu ...check
CVE-2026-10051In Eclipse Jetty, a first HTTP/1.1 request with trailers causes the se ...check, jetty9 might not be affected as not explicitly mentioned in the GhSA and still supported
CVE-2026-10420Untrusted pointer dereference vulnerability in Samsung Open Source mTo ...check
CVE-2026-10528A security flaw has been discovered in Orthanc DICOM Server up to 1.12 ...check, uderlying issue in src:dcmtk and should the CVE be associated with it? Cf. #1138713
CVE-2026-13500A weakness has been identified in antlr ANTLR4 up to 4.13.2. Affected ...check upstream reporting and status
CVE-2026-13501A security vulnerability has been detected in antlr ANTLR4 up to 4.13. ...check upstream reporting and status
CVE-2026-13502A flaw has been found in antlr ANTLR4 up to 4.13.2. This affects the f ...check upstream reporting and status
CVE-2026-13503A vulnerability was detected in antlr ANTLR4 up to 4.13.2. Affected by ...check upstream reporting and status
CVE-2026-14199Only self-managed Grafana instances with Auth Proxy authentication and ...check
CVE-2026-15779A flaw was found in samba's pam_winbind. When mkhomedir is enabled, pa ...check if Red Hat specific
CVE-2026-15816A flaw was found in dracut. The die() error-handling function writes i ...check
CVE-2026-16231hbs is an Express view engine that wraps Handlebars. Its registerAsync ...check
CVE-2026-16493A flaw was found in ansible-core. The _extract_collection_from_git() f ...check upstream details
CVE-2026-16566check upstream report and status on fix
CVE-2026-17523A flaw was found in the Linux kernel in net/can/bcm.c in can: bcm, whe ...wait, contacted CNAs (Red Hat and Linux Kernel CNA) for proper reassignment
CVE-2026-18210Improper neutralization of special elements used in an SQL command ('S ...check
CVE-2026-18329Description NGINX JavaScript (njs)and QuickJS (qjs) engineshave a vul ...check
CVE-2026-18358A flaw was found in gnome-remote-desktop as shipped in Red Hat Enterpr ...does not affect an upstream version, but need to check if still only Red Hat specific, check details RH bug
CVE-2026-18630Improper neutralization of special elements used in an SQL command ('S ...check
CVE-2026-18765Improper neutralization of special elements used in an SQL command ('S ...check
CVE-2026-18771Missing authentication for critical function vulnerability in TMT Mach ...check
CVE-2026-18780Cross-Site request forgery (CSRF) vulnerability in TMT Machine Industr ...check
CVE-2026-18808Improper Control of Generation of Code ('Code Injection') vulnerabilit ...check
CVE-2026-18931Use of Hard-coded Credentials vulnerability in TMT Machine Industry an ...check
CVE-2026-19032jackson-databind's deserializer for java.nio.file.Path resolves an att ...check
CVE-2026-19117Under specific conditions, an attacker can register an attacker-contro ...check
CVE-2026-19197A user with organization administrator permissions can delete dashboar ...check
CVE-2026-19410An Incorrect Authorization vulnerability in GitHub Trigger Comment Con ...check
CVE-2026-19475An authenticated user with permission to query a SQL data source can b ...check
CVE-2026-19616Missing Authorization vulnerability in TBC Technology Inc. KitLogistic ...check
CVE-2026-19702Improper neutralization of special elements used in an OS command ('OS ...check
CVE-2026-19754Baserow 2.3.3 contains a SQL injection vulnerability in the index() fo ...check
CVE-2026-19820A vulnerability in the Backblaze Client allows a local user to make th ...check
CVE-2026-20337A vulnerability in the zip archive parser of ClamAV could allow an una ...check
CVE-2026-20338A vulnerability in the zip archive parser of ClamAV could allow an una ...check
CVE-2026-20354Multiple vulnerabilities in the Secure/Multipurpose Internet Mail Exte ...check
CVE-2026-20355Multiple vulnerabilities in the Secure/Multipurpose Internet Mail Exte ...check
CVE-2026-22739Vulnerability in Spring Cloud when substituting the profile parameter ...check
CVE-2026-23479Redis is an in-memory data structure store. In redis-server from 7.2.0 ...check redict and valkey
CVE-2026-23631Redis is an in-memory data structure store. In all versions of redis-s ...check redict and valkey
CVE-2026-24182NVIDIA Display Driver for Windows and Linux contains a vulnerability w ...check
CVE-2026-24187NVIDIA Display Driver for Linux contains a vulnerability where an atta ...check
CVE-2026-24190NVIDIA Display Driver for Windows and Linux contains a vulnerability i ...check
CVE-2026-24192NVIDIA Display Driver for Linux contains a vulnerability where an atta ...check
CVE-2026-24193NVIDIA Display Driver for Windows and Linux contains a vulnerability w ...check
CVE-2026-24194NVIDIA Display Driver for Linux contains a vulnerability in a kernel m ...check
CVE-2026-24195NVIDIA Display Driver for Linux contains a vulnerability in UVM, where ...check
CVE-2026-24196NVIDIA Display Driver for Linux contains a vulnerability where a user ...check
CVE-2026-24197NVIDIA Display Driver for Linux contains a vulnerability in the Multi- ...check
CVE-2026-24198NVIDIA GPU Display Driver for Linux contains a vulnerability where an ...check
CVE-2026-24199NVIDIA Display Driver for Linux contains a vulnerability in a kernel m ...check
CVE-2026-25243Redis is an in-memory data structure store. In versions of redis-serve ...check redict and valkey
CVE-2026-25706Improper neutralization of special elements used in an OS command in y ...check
CVE-2026-27970Angular is a development platform for building mobile and desktop web ...check status for older versions
CVE-2026-28343CKEditor 5 is a modern JavaScript rich-text editor with an MVC archite ...check
CVE-2026-28687ImageMagick is free and open-source software used for editing and mani ...For imagemagick6 superseded by fix inside jumbo patch for CVE-2026-28686, first patch was incomplete
CVE-2026-28687ImageMagick is free and open-source software used for editing and mani ...Fixed by: https://github.com/ImageMagick/ImageMagick6/commit/6a602fb36f181a0089848344a3b0d79fc6155a2b (6.9.13-41)
CVE-2026-28688ImageMagick is free and open-source software used for editing and mani ...For imagemagick6 by fix inside jumbo patch for CVE-2026-28686, first patch was incomplete
CVE-2026-28688ImageMagick is free and open-source software used for editing and mani ...Fixed by: https://github.com/ImageMagick/ImageMagick6/commit/6a602fb36f181a0089848344a3b0d79fc6155a2b (6.9.13-41)
CVE-2026-29022dr_libs dr_wav.h version 0.14.4 and earlier (fixed in commit 8a7258c) ...qtads, dosbox-x, roc-toolkit, octave-ltfat, faudio bundle a copy, check security impact
CVE-2026-29036cJSON versions 1.5.0 through 1.7.19 contain an incorrectly-resolved na ...check, report upstream status
CVE-2026-30478A Dynamic-link Library Injection vulnerability in GatewayGeo MapServer ...check
CVE-2026-30479A Dynamic-link Library Injection vulnerability in OSGeo Project MapSer ...check
CVE-2026-31053A double free vulnerability exists in librz/bin/format/le/le.c in the ...check
CVE-2026-32148Insufficient Verification of Data Authenticity vulnerability in hexpm ...check
CVE-2026-32313xmlseclibs is a library written in PHP for working with XML Encryption ...check
CVE-2026-32600xml-security is a library that implements XML signatures and encryptio ...check
CVE-2026-32635Angular is a development platform for building mobile and desktop web ...check status for older versions
CVE-2026-34240JOSE is a Javascript Object Signing and Encryption (JOSE) library. Pri ...check
CVE-2026-36499A missing upper-bound check in the udpif_set_threads() function of Ope ...check, unclear status/validity
CVE-2026-39178A SQL injection vulnerability in SOGo before 5.12.7 allows authenticat ...CVE-2026-39178 and CVE-2026-39179 are duplicates of CVE-2026-46445 and CVE-2026-46446, CNA contacted
CVE-2026-39179A SQL injection vulnerability in SOGo before 5.12.7 allows authenticat ...CVE-2026-39178 and CVE-2026-39179 are duplicates of CVE-2026-46445 and CVE-2026-46446, CNA contacted
CVE-2026-39860Nix is a package manager for Linux and other Unix systems. A bug in th ...check, potentially affecting guix if same issue in backporting fix for CVE-2024-2729
CVE-2026-40033FreeRDP before 3.26.0 contains a heap-buffer-overflow vulnerability in ...unclear fixing commit references, incorrect reference in CVE entry?
CVE-2026-41889pgx is a PostgreSQL driver and toolkit for Go. Prior to version 5.9.2, ...check the other golang-github-jackc-pgx* sources
CVE-2026-42199Grid is a data structure grid for rust. From version 0.17.0 to before ...check
CVE-2026-42308Pillow is a Python imaging library. Prior to version 12.2.0, if a font ...research fixing commit(s), maybe https://github.com/python-pillow/Pillow/pull/9518/changes
CVE-2026-42503gopls by default communicates via pipe. However, -port and -listen fla ...check impact on golang-golang-x-tools
CVE-2026-43627llama.cpp builds b1283 through b9058 contain an integer overflow vulne ...check
CVE-2026-43628llama.cpp builds b3978 through b9058 contain an integer underflow and ...check
CVE-2026-43629llama.cpp builds b4882 through b9058 contain a heap buffer overflow vu ...check
CVE-2026-43631llama.cpp builds b7492 through the latest b9060 contains a use-after-f ...check
CVE-2026-43632llama.cpp builds b7492 through the latest b9060 contains a use-after-f ...check
CVE-2026-43829Full details and mitigation steps are currently restricted and will be ...check
CVE-2026-43830Full details and mitigation steps are currently restricted and will be ...check
CVE-2026-43831Full details and mitigation steps are currently restricted and will be ...check
CVE-2026-43832Full details and mitigation steps are currently restricted and will be ...check
CVE-2026-43833Full details and mitigation steps are currently restricted and will be ...check
CVE-2026-44933`PluginScript` attempts to `chroot` the plugin to the `repoManagerRoot ...check
CVE-2026-45221Konga before 2.1.0 contains a privilege escalation vulnerability that ...check
CVE-2026-45388In OCaml-TLS before 2.1.0, the client implementation does insufficient ...check
CVE-2026-45389In OCaml-TLS before 2.1.0, the server implementation does insufficient ...check
CVE-2026-45390In OCaml-tar before 3.4.0, a crafted archive with ../ path segments in ...check
CVE-2026-45730Nuclio is a "Serverless" framework for Real-Time Events and Data Proce ...check
CVE-2026-46727An issue was discovered in Ruby 4 before 4.0.5. A race condition leadi ...check
CVE-2026-47857In Reactor Core, applications that use the Flux.windowTimeout operator ...check
CVE-2026-47863In Reactor Core, applications that use the Flux.bufferTimeout operator ...check
CVE-2026-47875Applications that deserialize execution contexts with Jackson2Executio ...check
CVE-2026-47878DefaultExecutionContextSerializer, used by default in Spring Batch's J ...check
CVE-2026-47881Spring Batch's FlatFileItemReader supports files where a single logica ...check
CVE-2026-47883UrlHandlerFilter can be vulnerable to an open redirect when configured ...check
CVE-2026-47884Use of XsltView in a Spring MVC application can result in SSRF and RCE ...check
CVE-2026-47885The PartEventHttpMessageReader in Spring WebFlux does not enforce the ...check
CVE-2026-47886Applications that evaluate user-supplied Spring Expression Language (S ...check
CVE-2026-47887A Spring MVC application that uses UrlFileNameViewController that is m ...check
CVE-2026-47888A Spring RSocket application is exposed to a memory leak via a malform ...check
CVE-2026-47889A WebFlux application running on the Jetty 12 Core reactive adapter se ...check
CVE-2026-47890Spring MVC and WebFlux applications are vulnerable to stream corruptio ...check
CVE-2026-47891A Spring WebFlux application that relies on the Aalto XML processor to ...check
CVE-2026-47892A WebFlux application using functional endpoints and deployed with Dis ...check
CVE-2026-47893A Spring WebFlux application that supports WebSocket connections may e ...check
CVE-2026-48809python-engineio is a Python implementation of the Engine.IO realtime c ...checking upstream commit fixing issue, confusing infomation advisory claims both 4.13.2 and 4.13.5 to fix issue
CVE-2026-48932A flaw in Node.js HTTP client can cause a request desynchronization fo ...check
CVE-2026-49249Boruta is a standalone authorization server that aims to implement OAu ...check
CVE-2026-49830DSpace open source software is a repository application which provides ...check
CVE-2026-49831DSpace open source software is a repository application which provides ...check
CVE-2026-49832DSpace open source software is a repository application which provides ...check
CVE-2026-49833DSpace open source software is a repository application which provides ...check
CVE-2026-51152Server-side request forgery (SSRF) in the /har/test endpoint in QD 202 ...check
CVE-2026-51153Stored Cross-Site Scripting (XSS) in TaskRunHandler.post() in web/hand ...check
CVE-2026-51400An issue in Vim Project v9.2.0389 and earlier allows a local attacker ...check, possibly not reported upstream, only reporter reference in github gist
CVE-2026-51401An issue in Vim Project v9.2.0389 and earlier allows a local attacker ...check, possibly not reported upstream, only reporter reference in github gist
CVE-2026-51788An issue in cleverange_auth v.0.1.10 allows a remote attacker to cause ...check
CVE-2026-51956A Broken Object Level Authorization vulnerability exists in Grashjs At ...check
CVE-2026-51974An eval() injection vulnerability in the get_list function in modules/ ...check
CVE-2026-52022An issue in kamailio v.6.1.1 and before allows a remote attacker to ca ...check
CVE-2026-52023An issue in kamailio v.6.1.1 and before allows a remote attacker to ca ...check
CVE-2026-52111An issue in fast-note-sync-service <=2.13.7 allows a remote attacker t ...check
CVE-2026-52130llama.cpp b5693 and before is vulnerable to Uncontrolled Recursion in ...check
CVE-2026-52131llama.cpp b5693 and before has a Reachable Assertion via the gguf_read ...check
CVE-2026-52132llama.cpp through commit 97f06e9, when started with the --reranking fl ...check
CVE-2026-52730Xibo is an open source digital signage platform with a web content man ...check
CVE-2026-52831Nuclio is a "Serverless" framework for Real-Time Events and Data Proce ...check
CVE-2026-52832Nuclio is a "Serverless" framework for Real-Time Events and Data Proce ...check
CVE-2026-52833Nuclio is a "Serverless" framework for Real-Time Events and Data Proce ...check
CVE-2026-53507oasdiff-action is a GitHub Action that detects breaking changes in Ope ...check
CVE-2026-53508oasdiff is a command-line and Go package that compares and detects bre ...check
CVE-2026-53552Goploy is an open-source automation deployment system. In versions 1.1 ...check
CVE-2026-53553Goploy is an open-source automation deployment system. Prior to versio ...check
CVE-2026-53600async-tar is a tar archive reading/writing library for async Rust. Pri ...check
CVE-2026-53611Looking Glass is a modern, stateless network-diagnostic platform \u201 ...check
CVE-2026-53635Open edX Platform enables the authoring and delivery of online learnin ...check
CVE-2026-53636Open edX Platform enables the authoring and delivery of online learnin ...check
CVE-2026-53649Joro is a web exploitation framework. Prior to version 1.1.1, Joro's d ...check
CVE-2026-53670PREVAIL is a Polynomial-Runtime EBPF Verifier using an Abstract Interp ...check
CVE-2026-53671PREVAIL is a Polynomial-Runtime EBPF Verifier using an Abstract Interp ...check
CVE-2026-53683reset_password.html parses query string parameters and uses the 'url' ...check
CVE-2026-53706PREVAIL is a Polynomial-Runtime EBPF Verifier using an Abstract Interp ...check
CVE-2026-54179backpack/crud provides Create, Read, Update & Delete (CRUD) functions ...check
CVE-2026-55221Boruta is a standalone authorization server that aims to implement OAu ...check
CVE-2026-55223c3p0 is a JDBC Connection pooling library. In versions prior to 0.14.0 ...check if that is an issue with the packaged version
CVE-2026-55421Open edX Platform enables the authoring and delivery of online learnin ...check
CVE-2026-55663mediasoup is a WebRTC video conferencing system. From version 3.20.0 u ...check
CVE-2026-55951The Erlang/OTP httpc HTTP client does not enforce a limit on the total ...check
CVE-2026-56684Valkey is a distributed key-value database. Prior to 7.2.14, 8.0.10, 8 ...check redis and redict
CVE-2026-56816Netty is a network application framework for development of protocol s ...check, potentially only in 4.2.y series
CVE-2026-56818Netty is an asynchronous, event-driven network application framework. ...check missing upstream GHSA
CVE-2026-57862Kanboard 1.2.52 and prior contains a server-side request forgery vulne ...check upstream report
CVE-2026-58301When Apache Shiro is used with the Jakarta EE integration module, a lo ...check
CVE-2026-59111Improper neutralization of special elements used in an OS command ('OS ...check
CVE-2026-59680An OS command injection vulnerability was found in yast2-users. When d ...check
CVE-2026-59681A OS command injection vulnerability in yast2-auth-client allows an at ...check
CVE-2026-59696Improper Validation of Specified Quantity in Input vulnerability in Er ...check
CVE-2026-61711BuildKit is a toolkit for converting source code to build artifacts in ...check security impact on docker.io
CVE-2026-61712BuildKit is a toolkit for converting source code to build artifacts in ...check potential security impact on docker.io
CVE-2026-61750NVIDIA Megatron Bridge contains a vulnerability where an attacker coul ...check
CVE-2026-61751NVIDIA Megatron Bridge contains a vulnerability where an attacker coul ...check
CVE-2026-61752NVIDIA Megatron Bridge contains a vulnerability where an attacker coul ...check
CVE-2026-61753NVIDIA Megatron Bridge contains a vulnerability where an attacker coul ...check
CVE-2026-61754NVIDIA Megatron Bridge contains a vulnerability where an attacker coul ...check
CVE-2026-61755NVIDIA Megatron Bridge contains a vulnerability where an attacker coul ...check
CVE-2026-61756NVIDIA Megatron Bridge contains a vulnerability where an attacker coul ...check
CVE-2026-61757NVIDIA Megatron Bridge contains a vulnerability where an attacker coul ...check
CVE-2026-61758NVIDIA Megatron Bridge contains a vulnerability where an attacker coul ...check
CVE-2026-61759NVIDIA Megatron Bridge contains a vulnerability where an attacker coul ...check
CVE-2026-61760NVIDIA Megatron Bridge contains a vulnerability where an attacker coul ...check
CVE-2026-61761NVIDIA Megatron Bridge contains a vulnerability where an attacker coul ...check
CVE-2026-61762NVIDIA Megatron Bridge contains a vulnerability where an attacker coul ...check
CVE-2026-61763NVIDIA Megatron Bridge contains a vulnerability where an attacker coul ...check
CVE-2026-61764NVIDIA Megatron Bridge contains a vulnerability where an attacker coul ...check
CVE-2026-61765NVIDIA Megatron Bridge contains a vulnerability where an attacker coul ...check
CVE-2026-61766NVIDIA Megatron Bridge contains a vulnerability where an attacker coul ...check
CVE-2026-61767NVIDIA Megatron Bridge contains a vulnerability where an attacker coul ...check
CVE-2026-61768NVIDIA Megatron Bridge contains a vulnerability where an attacker coul ...check
CVE-2026-61769NVIDIA Megatron Bridge contains a vulnerability where an attacker coul ...check
CVE-2026-61770NVIDIA Megatron Bridge contains a vulnerability where an attacker coul ...check
CVE-2026-61771NVIDIA Megatron Bridge contains a vulnerability where an attacker coul ...check
CVE-2026-61772NVIDIA Megatron Bridge contains a vulnerability where an attacker coul ...check
CVE-2026-61773NVIDIA Megatron Bridge contains a vulnerability where an attacker coul ...check
CVE-2026-61774NVIDIA Megatron Bridge contains a vulnerability where an attacker coul ...check
CVE-2026-61775NVIDIA Megatron Bridge contains a vulnerability where an attacker coul ...check
CVE-2026-61776NVIDIA Megatron Bridge contains a vulnerability where an attacker coul ...check
CVE-2026-61777NVIDIA Megatron Bridge contains a vulnerability where an attacker coul ...check
CVE-2026-61778NVIDIA Megatron Bridge contains a vulnerability where an attacker coul ...check
CVE-2026-61779NVIDIA Megatron Bridge contains a vulnerability where an attacker coul ...check
CVE-2026-62993Smarty is a template engine for PHP, facilitating the separation of pr ...check
CVE-2026-63435Mail is an internet library for Ruby designed to handle email generati ...check
CVE-2026-63639Valkey is a distributed key-value database. Prior to 7.2.14, 8.0.10, 8 ...check redis and redict
CVE-2026-64611A flaw was found in libcupsfilters. The cfIEEE1284NormalizeMakeModel() ...check use in embedded cups, cups-filters
CVE-2026-66047ProfilePress (wp-user-avatar) WordPress plugin before 4.17.2 contains ...check
CVE-2026-66357httpd has never implemented obs-fold (RFC 2616 \xa72.2 / RFC 7230 \xa7 ...check
CVE-2026-66362Description: When NGINX Plus is configured as the data plane for NGINX ...check
CVE-2026-66835Path Equivalence vulnerability in Erlang/OTP inets httpd allows a remo ...check
CVE-2026-66842BIG-IP has a vulnerability where an authenticated user of any role may ...check
CVE-2026-67394A critical local privilege escalation via OS command injection vulnera ...check
CVE-2026-67395A path traversal vulnerability exists in Sage Employee Self Service\u2 ...check
CVE-2026-69664Missing Release of Resource after Effective Lifetime vulnerability in ...check
CVE-2026-70399Allocation of Resources Without Limits or Throttling vulnerability in ...check
CVE-2026-70405Improper Validation of Specified Quantity in Input vulnerability in Er ...check
CVE-2026-70409Improper Validation of Specified Quantity in Input vulnerability in Er ...check
CVE-2026-71054Vulnerability in Oracle Java SE (component: 2D). Supported versions t ...check
CVE-2026-71261dr_libs dr_wav.h (all versions through current master) contains an int ...check if embedded copy has security impact in roc-toolkit, qtads, qt6-multimedia, octave-ltfat, raylib, dosbox-x, mlpack and faudio
CVE-2026-71266tinyobjloader-c's tinyobj_parse_and_index_mtl_file (tinyobj_loader_c.h ...check
CVE-2026-71287Cacti's sanitize_sql_column (lib/functions.php) sanitizes user-supplie ...check, assigned from "Turan Security" CNA without further detailed references
CVE-2026-71380Missing Release of Resource after Effective Lifetime vulnerability in ...check
CVE-2026-71437Mermaid is a JavaScript tool that uses Markdown-inspired text to creat ...check introducing commit for further assessment
CVE-2026-71439Mermaid is a JavaScript tool that uses Markdown-inspired text to creat ...check introducing commit, might then be only 11.6.0 and above.
CVE-2026-71562Improper Validation of Specified Quantity in Input vulnerability in Er ...check
CVE-2026-72001Pangolin before 1.22.0 contains an authentication bypass vulnerability ...check
CVE-2026-72556A remote code execution vulnerability in ZoneMinder 1.39.17 allows any ...check, another CVE assigned by "Turan Security" CNA without providing details
CVE-2026-73270Improper Handling of Case Sensitivity vulnerability in Erlang/OTP inet ...check
CVE-2026-73276Gracefulness code ignored cases that should be rejected, resulting in ...check
CVE-2026-73812httpd function check_header/3 rejects duplicate Content-Length (per CV ...check
CVE-2026-73819The affectedEbyte product's vendor configuration utility permits acc ...check
CVE-2026-74835The inets application HTTP server httpd fails to enforce a configured ...check
CVE-2026-74837Allocation of Resources Without Limits or Throttling vulnerability in ...check
CVE-2026-74994The mod_auth module in OTP's inets httpd server, when configured with ...check
CVE-2026-75538An attacker that connects to an open Erlang TCP port that uses the ine ...check
CVE-2026-75593BuildKit is a toolkit for converting source code to build artifacts in ...check security impact on docker.io
CVE-2026-75758Uncontrolled Recursion vulnerability in the Elixir standard library al ...check
CVE-2026-75759Improper Verification of Cryptographic Signature vulnerability in erle ...check
CVE-2026-76060An authenticated OS command injection vulnerability exists in ZoneMind ...check
CVE-2026-78012An issue in the NetStaX EtherNet/IP Stack prior to v5.6.1 could allow ...check
CVE-2026-78178A vulnerability was determined in jQWidgets up to 24.0.1. This affects ...check
CVE-2026-78222A vulnerability exists in NGINX JavaScript where a malformed HTTP resp ...check
CVE-2026-78408The nsenter --join-cgroup option opens the target cgroup.procs file as ...check
CVE-2026-78409The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 ...check
CVE-2026-78410A flaw was found in util-linux. Restricted bind mounts take the source ...check
CVE-2026-78584Observable Response Discrepancy (CWE-204) in the Kibana Osquery featur ...check
CVE-2026-78586Allocation of Resources Without Limits or Throttling (CWE-770) in Kiba ...check
CVE-2026-78587Incorrect Authorization (CWE-863) in Fleet Server can lead to a denial ...check
CVE-2026-78588Allocation of Resources Without Limits or Throttling (CWE-770) in File ...check
CVE-2026-78590Improper Limitation of a Pathname to a Restricted Directory ('Path Tra ...check
CVE-2026-78591Improper Limitation of a Pathname to a Restricted Directory ('Path Tra ...check
CVE-2026-78594Improper Handling of Highly Compressed Data (CWE-409) in APM Server ca ...check
CVE-2026-78598Incorrect Authorization (CWE-863) in the Kibana machine learning featu ...check
CVE-2026-78599Improper Limitation of a Pathname to a Restricted Directory ('Path Tra ...check
CVE-2026-78600Incomplete Cleanup (CWE-459) in Elastic Cloud on Kubernetes (ECK) can ...check
CVE-2026-78601Missing Authorization (CWE-862) in Kibana can lead to information disc ...check
CVE-2026-78602Improper Limitation of a Pathname to a Restricted Directory ('Path Tra ...check
CVE-2026-78604Incorrect Permission Assignment for Critical Resource (CWE-732) in Ela ...check
CVE-2026-78609Incorrect Authorization (CWE-863) in Elastic Cloud on Kubernetes (ECK) ...check
CVE-2026-78689Description NGINX JavaScript (njs) has a vulnerability in the XML mo ...check
CVE-2026-79754Nuclio is a "Serverless" framework for Real-Time Events and Data Proce ...check
CVE-2026-79755Nuclio is a "Serverless" framework for Real-Time Events and Data Proce ...check
CVE-2026-79756Nuclio is a "Serverless" framework for Real-Time Events and Data Proce ...check
CVE-2026-79989The vulnerability allows any authenticated user to change their own pa ...check
CVE-2026-80047A vulnerability in Hugging Face Transformers (versions >= 4.49.0 and < ...check
CVE-2026-81267A malicious webpage could stall a popup's cross-origin navigation afte ...check
CVE-2026-82248gix-worktree-state before 0.33.0 (part of gitoxide) allows writing fil ...check
CVE-2026-82249gitoxide before 0.38.2 fails to validate carriage return characters in ...check
CVE-2026-82251gitoxide before 0.52.1 fails to validate submodule names from .gitmodu ...check
CVE-2026-82252gitoxide before 0.52.1 follows symlinks when reading the worktree .git ...check
CVE-2026-82253gitoxide (Rust crates gix <= 0.72.0 and gix-validate <= 0.10.0) contai ...check
CVE-2026-82327A flaw was found in libsolv, a dependency-resolution library used by R ...check upstream status, no references from Red Hat
CVE-2026-82631A security flaw has been discovered in valkey-io valkey 9.1.0. The aff ...check resis and restic
CVE-2026-82677A vulnerability was determined in valkey-io valkey 9.1.0. Impacted is ...check redis, restic?
CVE-2026-84233A flaw was found in rpm. A local attacker could supply a specially cra ...check upstream details
CVE-2026-84310pypdf is a free and open-source pure-python PDF library. Prior to 6.16 ...check upstream references
CVE-2026-84311pypdf is a free and open-source pure-python PDF library. Prior to 6.16 ...check upstream references
TEMP-1142597-FFA22AGHSA-68ff-gq39-pqjm: relay: authentication bypass with the "plain" password hash algorithmcheck, GHSA-68ff-gq39-pqjm claims >= 4.3.0 but potentially since v2.9-rc1

Search for package or bug name: Reporting problems