| Bug | Description | Note |
|---|
| CVE-2016-1584 | In all versions of Unity8 a running but not active application on a la ... | check proper tracking update |
| CVE-2018-25246 | Wikipedia 12.0 contains a denial of service vulnerability that allows ... | check |
| CVE-2018-25305 | librsvg2-bin 2.40.13 contains a buffer overflow vulnerability that all ... | check |
| CVE-2018-25306 | PDFunite 0.41.0 contains a buffer overflow vulnerability that allows l ... | check |
| CVE-2019-25485 | R 3.4.4 on Windows x64 contains a buffer overflow vulnerability in the ... | check |
| CVE-2019-25683 | FileZilla 3.40.0 contains a denial of service vulnerability in the loc ... | check |
| CVE-2022-4996 | A flaw has been found in mruby 3.1.0. Affected is the function udiv of ... | check |
| CVE-2022-23538 | github.com/sylabs/scs-library-client is the Go client for the Singular ... | check details, might as well affect golang-github-apptainer-container-library-client |
| CVE-2022-50942 | Incinga Web 2.8.2 contains a client-side cross-site scripting vulnerab ... | check status upstream |
| CVE-2023-20511 | Release of an invalid pointer in the AMD kernel mode driver (KMD) coul ... | check |
| CVE-2023-26044 | react/http is an event-driven, streaming HTTP client and server implem ... | check, is embedded inicinga-php-thirdparty, icingaweb2-module-reactbundle possibly affected |
| CVE-2023-31308 | A malicious virtual function can invoke the certain command handlers i ... | check |
| CVE-2023-47268 | In libslic3r/GCode/PostProcessor.cpp in Prusa PrusaSlicer through 2.6. ... | check |
| CVE-2023-49316 | In Math/BinaryField.php in phpseclib 3 before 3.0.34, excessively larg ... | check if affecting ldap-account-manager or unused path |
| CVE-2023-50251 | php-svg-lib is an SVG file parsing / rendering library. Prior to versi ... | check, other packages are embedding the library: civicrm, icinga-php-thirdparty and icingaweb2 to be checked |
| CVE-2023-50252 | php-svg-lib is an SVG file parsing / rendering library. Prior to versi ... | check, other packages are embedding the library: civicrm, icinga-php-thirdparty and icingaweb2 to be checked |
| CVE-2023-50262 | Dompdf is an HTML to PDF converter for PHP. When parsing SVG images Do ... | check sources embedding php-dompdf if affected |
| CVE-2023-54356 | Kyverno versions 1.9.4 and earlier support insecure 3DES cipher suites ... | check |
| CVE-2024-7708 | For requests that have a body, but reading the body may end up in read ... | check |
| CVE-2024-14047 | A local vulnerability in the Winlogbeat Windows installer caused runti ... | check |
| CVE-2024-22420 | JupyterLab is an extensible environment for interactive and reproducib ... | check completeness, src:jupyter-notebook? |
| CVE-2024-22421 | JupyterLab is an extensible environment for interactive and reproducib ... | check completeness, src:jupyter-notebook? |
| CVE-2024-47091 | Privilege escalation in the mk_mysql agent plugin on Windows in Checkm ... | check |
| CVE-2024-54192 | An issue inTcpreplay v4.5.1 allows a local attacker to cause a denial ... | check |
| CVE-2025-4382 | A flaw was found in systems utilizing LUKS-encrypted disks with GRUB c ... | double check if vulnerability only considered present after grub_is_cli_disabled is introduced |
| CVE-2025-6499 | A vulnerability classified as problematic was found in vstakhov libucl ... | check if impacts security wise rspamd, which embeds libucl and uses it a compile time |
| CVE-2025-8671 | A mismatch caused by client-triggered server-sent stream resets betwee ... | check, some projects will assign own CVEs and should then be covered under that specific CVE instead |
| CVE-2025-8941 | A flaw was found in linux-pam. The pam_namespace module may improperly ... | check likely RedHat specific incomplete fix for CVE-2025-6020, but asked to pinpoint incomplete fixes |
| CVE-2025-11010 | A vulnerability has been found in vstakhov libucl up to 0.9.2. Affecte ... | check if impacts security wise rspamd, which embeds libucl and uses it a compile time |
| CVE-2025-11147 | Reflected cross-site scripting (XSS) in Apt-Cacher-NG v3.2.1. The vuln ... | clarifying with reporter and Eduard Bloch on the issue. |
| CVE-2025-14575 | An Uncontrolled Search Path Element vulnerability in the OpenSSL TLS b ... | check |
| CVE-2025-15569 | A flaw has been found in Artifex MuPDF up to 1.26.1 on Windows. The im ... | check |
| CVE-2025-15613 | Kyverno before v1.13.4 is vulnerable to server-side request forgery (S ... | check |
| CVE-2025-33221 | NVIDIA Display Driver for Windows and Linux contains a vulnerability i ... | check |
| CVE-2025-58064 | CKEditor 5 is a modern JavaScript rich-text editor with an MVC archite ... | check |
| CVE-2025-60796 | phpPgAdmin 7.13.0 and earlier contains multiple cross-site scripting ( ... | check, possibly not reported upstream |
| CVE-2025-60797 | phpPgAdmin 7.13.0 and earlier contains a SQL injection vulnerability i ... | check, possibly not reported upstream |
| CVE-2025-60798 | phpPgAdmin 7.13.0 and earlier contains a SQL injection vulnerability i ... | check, possibly not reported upstream |
| CVE-2025-60799 | phpPgAdmin 7.13.0 and earlier contains an incorrect access control vul ... | check, possibly not reported upstream |
| CVE-2025-61261 | A reflected cross-site scripting (XSS) vulnerability in CKeditor v46.1 ... | check |
| CVE-2025-61982 | An arbitrary code execution vulnerability exists in the Code Stream di ... | check upstream status |
| CVE-2025-63607 | TechStore 1.0 is vulnerable to Cross Site Scripting (XSS). In contact_ ... | check |
| CVE-2025-63913 | An issue was discovered in OpenSBI 1.3 allowing attackers to cause a d ... | check |
| CVE-2025-66578 | xmlseclibs is a library written in PHP for working with XML Encryption ... | check |
| CVE-2025-67108 | eProsima Fast-DDS v3.3 was discovered to contain improper validation f ... | check https://gist.github.com/lkloliver/81b5d5a8328d712dbfd497bf11dbe913, unclear if reported upstream |
| CVE-2025-69534 | Python-Markdown version 3.8 contain a vulnerability where malformed HT ... | Asking whether it really needs a backport: https://bugs.debian.org/1131896 |
| CVE-2025-69720 | The infocmp command-line tool in ncurses before 6.5-20251213 has a sta ... | check upstream status |
| CVE-2025-69969 | A lack of authentication and authorization mechanisms in the Bluetooth ... | check |
| CVE-2025-70887 | An issue in ralphje Signify before v.0.9.2 allows a remote attacker to ... | check |
| CVE-2026-0708 | A flaw was found in libucl. A remote attacker could exploit this by pr ... | check if impacts security wise rspamd, which embeds libucl and uses it a compile time |
| CVE-2026-1703 | When pip is installing and extracting a maliciously crafted wheel arch ... | check as well pipenv |
| CVE-2026-4813 | A vulnerability in the Lutece Core XSL export management module up to ... | check |
| CVE-2026-4833 | A weakness has been identified in Orc discount up to 3.0.1.2. This iss ... | check libtext-markdown-discount-perl, ruby-rdiscount, cantor, embedding discount; check if security impact present |
| CVE-2026-5422 | A path traversal vulnerability exists in jupyter-server version 2.17.0 ... | CNA contacted responsible for this CVE entry as this seems to be a duplicate of CVE-2026-35397 |
| CVE-2026-5956 | Improper neutralization of special elements used in an SQL command ('S ... | check |
| CVE-2026-6657 | A vulnerability in jupyter-server versions 1.12.0 through 2.17.0 allow ... | CNA contacted responsible for this CVE entry as this seems to be a duplicate of CVE-2026-40110 |
| CVE-2026-7701 | A security vulnerability has been detected in Telegram Desktop up to 6 ... | check upstream reports |
| CVE-2026-7790 | Uncontrolled Resource Consumption vulnerability in ninenines cowlib (c ... | check if embedded copy in rabbitmq-server is problematic |
| CVE-2026-8851 | SOGo versions 5.12.7 and prior contains a SQL injection vulnerability ... | check correctness |
| CVE-2026-8863 | Multiple Microsoft-sigend UEFI SHIM bootloaders are vulnerable to Secu ... | check |
| CVE-2026-10051 | In Eclipse Jetty, a first HTTP/1.1 request with trailers causes the se ... | check, jetty9 might not be affected as not explicitly mentioned in the GhSA and still supported |
| CVE-2026-10420 | Untrusted pointer dereference vulnerability in Samsung Open Source mTo ... | check |
| CVE-2026-10528 | A security flaw has been discovered in Orthanc DICOM Server up to 1.12 ... | check, uderlying issue in src:dcmtk and should the CVE be associated with it? Cf. #1138713 |
| CVE-2026-13500 | A weakness has been identified in antlr ANTLR4 up to 4.13.2. Affected ... | check upstream reporting and status |
| CVE-2026-13501 | A security vulnerability has been detected in antlr ANTLR4 up to 4.13. ... | check upstream reporting and status |
| CVE-2026-13502 | A flaw has been found in antlr ANTLR4 up to 4.13.2. This affects the f ... | check upstream reporting and status |
| CVE-2026-13503 | A vulnerability was detected in antlr ANTLR4 up to 4.13.2. Affected by ... | check upstream reporting and status |
| CVE-2026-14199 | Only self-managed Grafana instances with Auth Proxy authentication and ... | check |
| CVE-2026-15779 | A flaw was found in samba's pam_winbind. When mkhomedir is enabled, pa ... | check if Red Hat specific |
| CVE-2026-15816 | A flaw was found in dracut. The die() error-handling function writes i ... | check |
| CVE-2026-16231 | hbs is an Express view engine that wraps Handlebars. Its registerAsync ... | check |
| CVE-2026-16493 | A flaw was found in ansible-core. The _extract_collection_from_git() f ... | check upstream details |
| CVE-2026-16566 | | check upstream report and status on fix |
| CVE-2026-17523 | A flaw was found in the Linux kernel in net/can/bcm.c in can: bcm, whe ... | wait, contacted CNAs (Red Hat and Linux Kernel CNA) for proper reassignment |
| CVE-2026-18210 | Improper neutralization of special elements used in an SQL command ('S ... | check |
| CVE-2026-18329 | Description NGINX JavaScript (njs)and QuickJS (qjs) engineshave a vul ... | check |
| CVE-2026-18358 | A flaw was found in gnome-remote-desktop as shipped in Red Hat Enterpr ... | does not affect an upstream version, but need to check if still only Red Hat specific, check details RH bug |
| CVE-2026-18630 | Improper neutralization of special elements used in an SQL command ('S ... | check |
| CVE-2026-18765 | Improper neutralization of special elements used in an SQL command ('S ... | check |
| CVE-2026-18771 | Missing authentication for critical function vulnerability in TMT Mach ... | check |
| CVE-2026-18780 | Cross-Site request forgery (CSRF) vulnerability in TMT Machine Industr ... | check |
| CVE-2026-18808 | Improper Control of Generation of Code ('Code Injection') vulnerabilit ... | check |
| CVE-2026-18931 | Use of Hard-coded Credentials vulnerability in TMT Machine Industry an ... | check |
| CVE-2026-19032 | jackson-databind's deserializer for java.nio.file.Path resolves an att ... | check |
| CVE-2026-19117 | Under specific conditions, an attacker can register an attacker-contro ... | check |
| CVE-2026-19197 | A user with organization administrator permissions can delete dashboar ... | check |
| CVE-2026-19410 | An Incorrect Authorization vulnerability in GitHub Trigger Comment Con ... | check |
| CVE-2026-19475 | An authenticated user with permission to query a SQL data source can b ... | check |
| CVE-2026-19616 | Missing Authorization vulnerability in TBC Technology Inc. KitLogistic ... | check |
| CVE-2026-19702 | Improper neutralization of special elements used in an OS command ('OS ... | check |
| CVE-2026-19754 | Baserow 2.3.3 contains a SQL injection vulnerability in the index() fo ... | check |
| CVE-2026-19820 | A vulnerability in the Backblaze Client allows a local user to make th ... | check |
| CVE-2026-20337 | A vulnerability in the zip archive parser of ClamAV could allow an una ... | check |
| CVE-2026-20338 | A vulnerability in the zip archive parser of ClamAV could allow an una ... | check |
| CVE-2026-20354 | Multiple vulnerabilities in the Secure/Multipurpose Internet Mail Exte ... | check |
| CVE-2026-20355 | Multiple vulnerabilities in the Secure/Multipurpose Internet Mail Exte ... | check |
| CVE-2026-22739 | Vulnerability in Spring Cloud when substituting the profile parameter ... | check |
| CVE-2026-23479 | Redis is an in-memory data structure store. In redis-server from 7.2.0 ... | check redict and valkey |
| CVE-2026-23631 | Redis is an in-memory data structure store. In all versions of redis-s ... | check redict and valkey |
| CVE-2026-24182 | NVIDIA Display Driver for Windows and Linux contains a vulnerability w ... | check |
| CVE-2026-24187 | NVIDIA Display Driver for Linux contains a vulnerability where an atta ... | check |
| CVE-2026-24190 | NVIDIA Display Driver for Windows and Linux contains a vulnerability i ... | check |
| CVE-2026-24192 | NVIDIA Display Driver for Linux contains a vulnerability where an atta ... | check |
| CVE-2026-24193 | NVIDIA Display Driver for Windows and Linux contains a vulnerability w ... | check |
| CVE-2026-24194 | NVIDIA Display Driver for Linux contains a vulnerability in a kernel m ... | check |
| CVE-2026-24195 | NVIDIA Display Driver for Linux contains a vulnerability in UVM, where ... | check |
| CVE-2026-24196 | NVIDIA Display Driver for Linux contains a vulnerability where a user ... | check |
| CVE-2026-24197 | NVIDIA Display Driver for Linux contains a vulnerability in the Multi- ... | check |
| CVE-2026-24198 | NVIDIA GPU Display Driver for Linux contains a vulnerability where an ... | check |
| CVE-2026-24199 | NVIDIA Display Driver for Linux contains a vulnerability in a kernel m ... | check |
| CVE-2026-25243 | Redis is an in-memory data structure store. In versions of redis-serve ... | check redict and valkey |
| CVE-2026-25706 | Improper neutralization of special elements used in an OS command in y ... | check |
| CVE-2026-27970 | Angular is a development platform for building mobile and desktop web ... | check status for older versions |
| CVE-2026-28343 | CKEditor 5 is a modern JavaScript rich-text editor with an MVC archite ... | check |
| CVE-2026-28687 | ImageMagick is free and open-source software used for editing and mani ... | For imagemagick6 superseded by fix inside jumbo patch for CVE-2026-28686, first patch was incomplete |
| CVE-2026-28687 | ImageMagick is free and open-source software used for editing and mani ... | Fixed by: https://github.com/ImageMagick/ImageMagick6/commit/6a602fb36f181a0089848344a3b0d79fc6155a2b (6.9.13-41) |
| CVE-2026-28688 | ImageMagick is free and open-source software used for editing and mani ... | For imagemagick6 by fix inside jumbo patch for CVE-2026-28686, first patch was incomplete |
| CVE-2026-28688 | ImageMagick is free and open-source software used for editing and mani ... | Fixed by: https://github.com/ImageMagick/ImageMagick6/commit/6a602fb36f181a0089848344a3b0d79fc6155a2b (6.9.13-41) |
| CVE-2026-29022 | dr_libs dr_wav.h version 0.14.4 and earlier (fixed in commit 8a7258c) ... | qtads, dosbox-x, roc-toolkit, octave-ltfat, faudio bundle a copy, check security impact |
| CVE-2026-29036 | cJSON versions 1.5.0 through 1.7.19 contain an incorrectly-resolved na ... | check, report upstream status |
| CVE-2026-30478 | A Dynamic-link Library Injection vulnerability in GatewayGeo MapServer ... | check |
| CVE-2026-30479 | A Dynamic-link Library Injection vulnerability in OSGeo Project MapSer ... | check |
| CVE-2026-31053 | A double free vulnerability exists in librz/bin/format/le/le.c in the ... | check |
| CVE-2026-32148 | Insufficient Verification of Data Authenticity vulnerability in hexpm ... | check |
| CVE-2026-32313 | xmlseclibs is a library written in PHP for working with XML Encryption ... | check |
| CVE-2026-32600 | xml-security is a library that implements XML signatures and encryptio ... | check |
| CVE-2026-32635 | Angular is a development platform for building mobile and desktop web ... | check status for older versions |
| CVE-2026-34240 | JOSE is a Javascript Object Signing and Encryption (JOSE) library. Pri ... | check |
| CVE-2026-36499 | A missing upper-bound check in the udpif_set_threads() function of Ope ... | check, unclear status/validity |
| CVE-2026-39178 | A SQL injection vulnerability in SOGo before 5.12.7 allows authenticat ... | CVE-2026-39178 and CVE-2026-39179 are duplicates of CVE-2026-46445 and CVE-2026-46446, CNA contacted |
| CVE-2026-39179 | A SQL injection vulnerability in SOGo before 5.12.7 allows authenticat ... | CVE-2026-39178 and CVE-2026-39179 are duplicates of CVE-2026-46445 and CVE-2026-46446, CNA contacted |
| CVE-2026-39860 | Nix is a package manager for Linux and other Unix systems. A bug in th ... | check, potentially affecting guix if same issue in backporting fix for CVE-2024-2729 |
| CVE-2026-40033 | FreeRDP before 3.26.0 contains a heap-buffer-overflow vulnerability in ... | unclear fixing commit references, incorrect reference in CVE entry? |
| CVE-2026-41889 | pgx is a PostgreSQL driver and toolkit for Go. Prior to version 5.9.2, ... | check the other golang-github-jackc-pgx* sources |
| CVE-2026-42199 | Grid is a data structure grid for rust. From version 0.17.0 to before ... | check |
| CVE-2026-42308 | Pillow is a Python imaging library. Prior to version 12.2.0, if a font ... | research fixing commit(s), maybe https://github.com/python-pillow/Pillow/pull/9518/changes |
| CVE-2026-42503 | gopls by default communicates via pipe. However, -port and -listen fla ... | check impact on golang-golang-x-tools |
| CVE-2026-43627 | llama.cpp builds b1283 through b9058 contain an integer overflow vulne ... | check |
| CVE-2026-43628 | llama.cpp builds b3978 through b9058 contain an integer underflow and ... | check |
| CVE-2026-43629 | llama.cpp builds b4882 through b9058 contain a heap buffer overflow vu ... | check |
| CVE-2026-43631 | llama.cpp builds b7492 through the latest b9060 contains a use-after-f ... | check |
| CVE-2026-43632 | llama.cpp builds b7492 through the latest b9060 contains a use-after-f ... | check |
| CVE-2026-43829 | Full details and mitigation steps are currently restricted and will be ... | check |
| CVE-2026-43830 | Full details and mitigation steps are currently restricted and will be ... | check |
| CVE-2026-43831 | Full details and mitigation steps are currently restricted and will be ... | check |
| CVE-2026-43832 | Full details and mitigation steps are currently restricted and will be ... | check |
| CVE-2026-43833 | Full details and mitigation steps are currently restricted and will be ... | check |
| CVE-2026-44933 | `PluginScript` attempts to `chroot` the plugin to the `repoManagerRoot ... | check |
| CVE-2026-45221 | Konga before 2.1.0 contains a privilege escalation vulnerability that ... | check |
| CVE-2026-45388 | In OCaml-TLS before 2.1.0, the client implementation does insufficient ... | check |
| CVE-2026-45389 | In OCaml-TLS before 2.1.0, the server implementation does insufficient ... | check |
| CVE-2026-45390 | In OCaml-tar before 3.4.0, a crafted archive with ../ path segments in ... | check |
| CVE-2026-45730 | Nuclio is a "Serverless" framework for Real-Time Events and Data Proce ... | check |
| CVE-2026-46727 | An issue was discovered in Ruby 4 before 4.0.5. A race condition leadi ... | check |
| CVE-2026-47857 | In Reactor Core, applications that use the Flux.windowTimeout operator ... | check |
| CVE-2026-47863 | In Reactor Core, applications that use the Flux.bufferTimeout operator ... | check |
| CVE-2026-47875 | Applications that deserialize execution contexts with Jackson2Executio ... | check |
| CVE-2026-47878 | DefaultExecutionContextSerializer, used by default in Spring Batch's J ... | check |
| CVE-2026-47881 | Spring Batch's FlatFileItemReader supports files where a single logica ... | check |
| CVE-2026-47883 | UrlHandlerFilter can be vulnerable to an open redirect when configured ... | check |
| CVE-2026-47884 | Use of XsltView in a Spring MVC application can result in SSRF and RCE ... | check |
| CVE-2026-47885 | The PartEventHttpMessageReader in Spring WebFlux does not enforce the ... | check |
| CVE-2026-47886 | Applications that evaluate user-supplied Spring Expression Language (S ... | check |
| CVE-2026-47887 | A Spring MVC application that uses UrlFileNameViewController that is m ... | check |
| CVE-2026-47888 | A Spring RSocket application is exposed to a memory leak via a malform ... | check |
| CVE-2026-47889 | A WebFlux application running on the Jetty 12 Core reactive adapter se ... | check |
| CVE-2026-47890 | Spring MVC and WebFlux applications are vulnerable to stream corruptio ... | check |
| CVE-2026-47891 | A Spring WebFlux application that relies on the Aalto XML processor to ... | check |
| CVE-2026-47892 | A WebFlux application using functional endpoints and deployed with Dis ... | check |
| CVE-2026-47893 | A Spring WebFlux application that supports WebSocket connections may e ... | check |
| CVE-2026-48809 | python-engineio is a Python implementation of the Engine.IO realtime c ... | checking upstream commit fixing issue, confusing infomation advisory claims both 4.13.2 and 4.13.5 to fix issue |
| CVE-2026-48932 | A flaw in Node.js HTTP client can cause a request desynchronization fo ... | check |
| CVE-2026-49249 | Boruta is a standalone authorization server that aims to implement OAu ... | check |
| CVE-2026-49830 | DSpace open source software is a repository application which provides ... | check |
| CVE-2026-49831 | DSpace open source software is a repository application which provides ... | check |
| CVE-2026-49832 | DSpace open source software is a repository application which provides ... | check |
| CVE-2026-49833 | DSpace open source software is a repository application which provides ... | check |
| CVE-2026-51152 | Server-side request forgery (SSRF) in the /har/test endpoint in QD 202 ... | check |
| CVE-2026-51153 | Stored Cross-Site Scripting (XSS) in TaskRunHandler.post() in web/hand ... | check |
| CVE-2026-51400 | An issue in Vim Project v9.2.0389 and earlier allows a local attacker ... | check, possibly not reported upstream, only reporter reference in github gist |
| CVE-2026-51401 | An issue in Vim Project v9.2.0389 and earlier allows a local attacker ... | check, possibly not reported upstream, only reporter reference in github gist |
| CVE-2026-51788 | An issue in cleverange_auth v.0.1.10 allows a remote attacker to cause ... | check |
| CVE-2026-51956 | A Broken Object Level Authorization vulnerability exists in Grashjs At ... | check |
| CVE-2026-51974 | An eval() injection vulnerability in the get_list function in modules/ ... | check |
| CVE-2026-52022 | An issue in kamailio v.6.1.1 and before allows a remote attacker to ca ... | check |
| CVE-2026-52023 | An issue in kamailio v.6.1.1 and before allows a remote attacker to ca ... | check |
| CVE-2026-52111 | An issue in fast-note-sync-service <=2.13.7 allows a remote attacker t ... | check |
| CVE-2026-52130 | llama.cpp b5693 and before is vulnerable to Uncontrolled Recursion in ... | check |
| CVE-2026-52131 | llama.cpp b5693 and before has a Reachable Assertion via the gguf_read ... | check |
| CVE-2026-52132 | llama.cpp through commit 97f06e9, when started with the --reranking fl ... | check |
| CVE-2026-52730 | Xibo is an open source digital signage platform with a web content man ... | check |
| CVE-2026-52831 | Nuclio is a "Serverless" framework for Real-Time Events and Data Proce ... | check |
| CVE-2026-52832 | Nuclio is a "Serverless" framework for Real-Time Events and Data Proce ... | check |
| CVE-2026-52833 | Nuclio is a "Serverless" framework for Real-Time Events and Data Proce ... | check |
| CVE-2026-53507 | oasdiff-action is a GitHub Action that detects breaking changes in Ope ... | check |
| CVE-2026-53508 | oasdiff is a command-line and Go package that compares and detects bre ... | check |
| CVE-2026-53552 | Goploy is an open-source automation deployment system. In versions 1.1 ... | check |
| CVE-2026-53553 | Goploy is an open-source automation deployment system. Prior to versio ... | check |
| CVE-2026-53600 | async-tar is a tar archive reading/writing library for async Rust. Pri ... | check |
| CVE-2026-53611 | Looking Glass is a modern, stateless network-diagnostic platform \u201 ... | check |
| CVE-2026-53635 | Open edX Platform enables the authoring and delivery of online learnin ... | check |
| CVE-2026-53636 | Open edX Platform enables the authoring and delivery of online learnin ... | check |
| CVE-2026-53649 | Joro is a web exploitation framework. Prior to version 1.1.1, Joro's d ... | check |
| CVE-2026-53670 | PREVAIL is a Polynomial-Runtime EBPF Verifier using an Abstract Interp ... | check |
| CVE-2026-53671 | PREVAIL is a Polynomial-Runtime EBPF Verifier using an Abstract Interp ... | check |
| CVE-2026-53683 | reset_password.html parses query string parameters and uses the 'url' ... | check |
| CVE-2026-53706 | PREVAIL is a Polynomial-Runtime EBPF Verifier using an Abstract Interp ... | check |
| CVE-2026-54179 | backpack/crud provides Create, Read, Update & Delete (CRUD) functions ... | check |
| CVE-2026-55221 | Boruta is a standalone authorization server that aims to implement OAu ... | check |
| CVE-2026-55223 | c3p0 is a JDBC Connection pooling library. In versions prior to 0.14.0 ... | check if that is an issue with the packaged version |
| CVE-2026-55421 | Open edX Platform enables the authoring and delivery of online learnin ... | check |
| CVE-2026-55663 | mediasoup is a WebRTC video conferencing system. From version 3.20.0 u ... | check |
| CVE-2026-55951 | The Erlang/OTP httpc HTTP client does not enforce a limit on the total ... | check |
| CVE-2026-56684 | Valkey is a distributed key-value database. Prior to 7.2.14, 8.0.10, 8 ... | check redis and redict |
| CVE-2026-56816 | Netty is a network application framework for development of protocol s ... | check, potentially only in 4.2.y series |
| CVE-2026-56818 | Netty is an asynchronous, event-driven network application framework. ... | check missing upstream GHSA |
| CVE-2026-57862 | Kanboard 1.2.52 and prior contains a server-side request forgery vulne ... | check upstream report |
| CVE-2026-58301 | When Apache Shiro is used with the Jakarta EE integration module, a lo ... | check |
| CVE-2026-59111 | Improper neutralization of special elements used in an OS command ('OS ... | check |
| CVE-2026-59680 | An OS command injection vulnerability was found in yast2-users. When d ... | check |
| CVE-2026-59681 | A OS command injection vulnerability in yast2-auth-client allows an at ... | check |
| CVE-2026-59696 | Improper Validation of Specified Quantity in Input vulnerability in Er ... | check |
| CVE-2026-61711 | BuildKit is a toolkit for converting source code to build artifacts in ... | check security impact on docker.io |
| CVE-2026-61712 | BuildKit is a toolkit for converting source code to build artifacts in ... | check potential security impact on docker.io |
| CVE-2026-61750 | NVIDIA Megatron Bridge contains a vulnerability where an attacker coul ... | check |
| CVE-2026-61751 | NVIDIA Megatron Bridge contains a vulnerability where an attacker coul ... | check |
| CVE-2026-61752 | NVIDIA Megatron Bridge contains a vulnerability where an attacker coul ... | check |
| CVE-2026-61753 | NVIDIA Megatron Bridge contains a vulnerability where an attacker coul ... | check |
| CVE-2026-61754 | NVIDIA Megatron Bridge contains a vulnerability where an attacker coul ... | check |
| CVE-2026-61755 | NVIDIA Megatron Bridge contains a vulnerability where an attacker coul ... | check |
| CVE-2026-61756 | NVIDIA Megatron Bridge contains a vulnerability where an attacker coul ... | check |
| CVE-2026-61757 | NVIDIA Megatron Bridge contains a vulnerability where an attacker coul ... | check |
| CVE-2026-61758 | NVIDIA Megatron Bridge contains a vulnerability where an attacker coul ... | check |
| CVE-2026-61759 | NVIDIA Megatron Bridge contains a vulnerability where an attacker coul ... | check |
| CVE-2026-61760 | NVIDIA Megatron Bridge contains a vulnerability where an attacker coul ... | check |
| CVE-2026-61761 | NVIDIA Megatron Bridge contains a vulnerability where an attacker coul ... | check |
| CVE-2026-61762 | NVIDIA Megatron Bridge contains a vulnerability where an attacker coul ... | check |
| CVE-2026-61763 | NVIDIA Megatron Bridge contains a vulnerability where an attacker coul ... | check |
| CVE-2026-61764 | NVIDIA Megatron Bridge contains a vulnerability where an attacker coul ... | check |
| CVE-2026-61765 | NVIDIA Megatron Bridge contains a vulnerability where an attacker coul ... | check |
| CVE-2026-61766 | NVIDIA Megatron Bridge contains a vulnerability where an attacker coul ... | check |
| CVE-2026-61767 | NVIDIA Megatron Bridge contains a vulnerability where an attacker coul ... | check |
| CVE-2026-61768 | NVIDIA Megatron Bridge contains a vulnerability where an attacker coul ... | check |
| CVE-2026-61769 | NVIDIA Megatron Bridge contains a vulnerability where an attacker coul ... | check |
| CVE-2026-61770 | NVIDIA Megatron Bridge contains a vulnerability where an attacker coul ... | check |
| CVE-2026-61771 | NVIDIA Megatron Bridge contains a vulnerability where an attacker coul ... | check |
| CVE-2026-61772 | NVIDIA Megatron Bridge contains a vulnerability where an attacker coul ... | check |
| CVE-2026-61773 | NVIDIA Megatron Bridge contains a vulnerability where an attacker coul ... | check |
| CVE-2026-61774 | NVIDIA Megatron Bridge contains a vulnerability where an attacker coul ... | check |
| CVE-2026-61775 | NVIDIA Megatron Bridge contains a vulnerability where an attacker coul ... | check |
| CVE-2026-61776 | NVIDIA Megatron Bridge contains a vulnerability where an attacker coul ... | check |
| CVE-2026-61777 | NVIDIA Megatron Bridge contains a vulnerability where an attacker coul ... | check |
| CVE-2026-61778 | NVIDIA Megatron Bridge contains a vulnerability where an attacker coul ... | check |
| CVE-2026-61779 | NVIDIA Megatron Bridge contains a vulnerability where an attacker coul ... | check |
| CVE-2026-62993 | Smarty is a template engine for PHP, facilitating the separation of pr ... | check |
| CVE-2026-63435 | Mail is an internet library for Ruby designed to handle email generati ... | check |
| CVE-2026-63639 | Valkey is a distributed key-value database. Prior to 7.2.14, 8.0.10, 8 ... | check redis and redict |
| CVE-2026-64611 | A flaw was found in libcupsfilters. The cfIEEE1284NormalizeMakeModel() ... | check use in embedded cups, cups-filters |
| CVE-2026-66047 | ProfilePress (wp-user-avatar) WordPress plugin before 4.17.2 contains ... | check |
| CVE-2026-66357 | httpd has never implemented obs-fold (RFC 2616 \xa72.2 / RFC 7230 \xa7 ... | check |
| CVE-2026-66362 | Description: When NGINX Plus is configured as the data plane for NGINX ... | check |
| CVE-2026-66835 | Path Equivalence vulnerability in Erlang/OTP inets httpd allows a remo ... | check |
| CVE-2026-66842 | BIG-IP has a vulnerability where an authenticated user of any role may ... | check |
| CVE-2026-67394 | A critical local privilege escalation via OS command injection vulnera ... | check |
| CVE-2026-67395 | A path traversal vulnerability exists in Sage Employee Self Service\u2 ... | check |
| CVE-2026-69664 | Missing Release of Resource after Effective Lifetime vulnerability in ... | check |
| CVE-2026-70399 | Allocation of Resources Without Limits or Throttling vulnerability in ... | check |
| CVE-2026-70405 | Improper Validation of Specified Quantity in Input vulnerability in Er ... | check |
| CVE-2026-70409 | Improper Validation of Specified Quantity in Input vulnerability in Er ... | check |
| CVE-2026-71054 | Vulnerability in Oracle Java SE (component: 2D). Supported versions t ... | check |
| CVE-2026-71261 | dr_libs dr_wav.h (all versions through current master) contains an int ... | check if embedded copy has security impact in roc-toolkit, qtads, qt6-multimedia, octave-ltfat, raylib, dosbox-x, mlpack and faudio |
| CVE-2026-71266 | tinyobjloader-c's tinyobj_parse_and_index_mtl_file (tinyobj_loader_c.h ... | check |
| CVE-2026-71287 | Cacti's sanitize_sql_column (lib/functions.php) sanitizes user-supplie ... | check, assigned from "Turan Security" CNA without further detailed references |
| CVE-2026-71380 | Missing Release of Resource after Effective Lifetime vulnerability in ... | check |
| CVE-2026-71437 | Mermaid is a JavaScript tool that uses Markdown-inspired text to creat ... | check introducing commit for further assessment |
| CVE-2026-71439 | Mermaid is a JavaScript tool that uses Markdown-inspired text to creat ... | check introducing commit, might then be only 11.6.0 and above. |
| CVE-2026-71562 | Improper Validation of Specified Quantity in Input vulnerability in Er ... | check |
| CVE-2026-72001 | Pangolin before 1.22.0 contains an authentication bypass vulnerability ... | check |
| CVE-2026-72556 | A remote code execution vulnerability in ZoneMinder 1.39.17 allows any ... | check, another CVE assigned by "Turan Security" CNA without providing details |
| CVE-2026-73270 | Improper Handling of Case Sensitivity vulnerability in Erlang/OTP inet ... | check |
| CVE-2026-73276 | Gracefulness code ignored cases that should be rejected, resulting in ... | check |
| CVE-2026-73812 | httpd function check_header/3 rejects duplicate Content-Length (per CV ... | check |
| CVE-2026-73819 | The affectedEbyte product's vendor configuration utility permits acc ... | check |
| CVE-2026-74835 | The inets application HTTP server httpd fails to enforce a configured ... | check |
| CVE-2026-74837 | Allocation of Resources Without Limits or Throttling vulnerability in ... | check |
| CVE-2026-74994 | The mod_auth module in OTP's inets httpd server, when configured with ... | check |
| CVE-2026-75538 | An attacker that connects to an open Erlang TCP port that uses the ine ... | check |
| CVE-2026-75593 | BuildKit is a toolkit for converting source code to build artifacts in ... | check security impact on docker.io |
| CVE-2026-75758 | Uncontrolled Recursion vulnerability in the Elixir standard library al ... | check |
| CVE-2026-75759 | Improper Verification of Cryptographic Signature vulnerability in erle ... | check |
| CVE-2026-76060 | An authenticated OS command injection vulnerability exists in ZoneMind ... | check |
| CVE-2026-78012 | An issue in the NetStaX EtherNet/IP Stack prior to v5.6.1 could allow ... | check |
| CVE-2026-78178 | A vulnerability was determined in jQWidgets up to 24.0.1. This affects ... | check |
| CVE-2026-78222 | A vulnerability exists in NGINX JavaScript where a malformed HTTP resp ... | check |
| CVE-2026-78408 | The nsenter --join-cgroup option opens the target cgroup.procs file as ... | check |
| CVE-2026-78409 | The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 ... | check |
| CVE-2026-78410 | A flaw was found in util-linux. Restricted bind mounts take the source ... | check |
| CVE-2026-78584 | Observable Response Discrepancy (CWE-204) in the Kibana Osquery featur ... | check |
| CVE-2026-78586 | Allocation of Resources Without Limits or Throttling (CWE-770) in Kiba ... | check |
| CVE-2026-78587 | Incorrect Authorization (CWE-863) in Fleet Server can lead to a denial ... | check |
| CVE-2026-78588 | Allocation of Resources Without Limits or Throttling (CWE-770) in File ... | check |
| CVE-2026-78590 | Improper Limitation of a Pathname to a Restricted Directory ('Path Tra ... | check |
| CVE-2026-78591 | Improper Limitation of a Pathname to a Restricted Directory ('Path Tra ... | check |
| CVE-2026-78594 | Improper Handling of Highly Compressed Data (CWE-409) in APM Server ca ... | check |
| CVE-2026-78598 | Incorrect Authorization (CWE-863) in the Kibana machine learning featu ... | check |
| CVE-2026-78599 | Improper Limitation of a Pathname to a Restricted Directory ('Path Tra ... | check |
| CVE-2026-78600 | Incomplete Cleanup (CWE-459) in Elastic Cloud on Kubernetes (ECK) can ... | check |
| CVE-2026-78601 | Missing Authorization (CWE-862) in Kibana can lead to information disc ... | check |
| CVE-2026-78602 | Improper Limitation of a Pathname to a Restricted Directory ('Path Tra ... | check |
| CVE-2026-78604 | Incorrect Permission Assignment for Critical Resource (CWE-732) in Ela ... | check |
| CVE-2026-78609 | Incorrect Authorization (CWE-863) in Elastic Cloud on Kubernetes (ECK) ... | check |
| CVE-2026-78689 | Description NGINX JavaScript (njs) has a vulnerability in the XML mo ... | check |
| CVE-2026-79754 | Nuclio is a "Serverless" framework for Real-Time Events and Data Proce ... | check |
| CVE-2026-79755 | Nuclio is a "Serverless" framework for Real-Time Events and Data Proce ... | check |
| CVE-2026-79756 | Nuclio is a "Serverless" framework for Real-Time Events and Data Proce ... | check |
| CVE-2026-79989 | The vulnerability allows any authenticated user to change their own pa ... | check |
| CVE-2026-80047 | A vulnerability in Hugging Face Transformers (versions >= 4.49.0 and < ... | check |
| CVE-2026-81267 | A malicious webpage could stall a popup's cross-origin navigation afte ... | check |
| CVE-2026-82248 | gix-worktree-state before 0.33.0 (part of gitoxide) allows writing fil ... | check |
| CVE-2026-82249 | gitoxide before 0.38.2 fails to validate carriage return characters in ... | check |
| CVE-2026-82251 | gitoxide before 0.52.1 fails to validate submodule names from .gitmodu ... | check |
| CVE-2026-82252 | gitoxide before 0.52.1 follows symlinks when reading the worktree .git ... | check |
| CVE-2026-82253 | gitoxide (Rust crates gix <= 0.72.0 and gix-validate <= 0.10.0) contai ... | check |
| CVE-2026-82327 | A flaw was found in libsolv, a dependency-resolution library used by R ... | check upstream status, no references from Red Hat |
| CVE-2026-82631 | A security flaw has been discovered in valkey-io valkey 9.1.0. The aff ... | check resis and restic |
| CVE-2026-82677 | A vulnerability was determined in valkey-io valkey 9.1.0. Impacted is ... | check redis, restic? |
| CVE-2026-84233 | A flaw was found in rpm. A local attacker could supply a specially cra ... | check upstream details |
| CVE-2026-84310 | pypdf is a free and open-source pure-python PDF library. Prior to 6.16 ... | check upstream references |
| CVE-2026-84311 | pypdf is a free and open-source pure-python PDF library. Prior to 6.16 ... | check upstream references |
| TEMP-1142597-FFA22A | GHSA-68ff-gq39-pqjm: relay: authentication bypass with the "plain" password hash algorithm | check, GHSA-68ff-gq39-pqjm claims >= 4.3.0 but potentially since v2.9-rc1 |