| Bug | Description | Note |
|---|
| CVE-2016-1584 | In all versions of Unity8 a running but not active application on a la ... | check proper tracking update |
| CVE-2018-25246 | Wikipedia 12.0 contains a denial of service vulnerability that allows ... | check |
| CVE-2018-25305 | librsvg2-bin 2.40.13 contains a buffer overflow vulnerability that all ... | check |
| CVE-2018-25306 | PDFunite 0.41.0 contains a buffer overflow vulnerability that allows l ... | check |
| CVE-2019-25485 | R 3.4.4 on Windows x64 contains a buffer overflow vulnerability in the ... | check |
| CVE-2019-25683 | FileZilla 3.40.0 contains a denial of service vulnerability in the loc ... | check |
| CVE-2019-25766 | Renovate versions >= 13.87.0 and <= 19.38.6 leak temporary repository ... | check |
| CVE-2020-37267 | Renovate versions >=19.180.0 and <23.25.1, when used with Azure DevOps ... | check |
| CVE-2021-43716 | Verification Bypass vulnerability exists in EPSON 150075647YWWV110 Eas ... | check |
| CVE-2021-43717 | An issue exists in pson EH-TW5350 Epson iProjection.apk v3.2.6. If you ... | check |
| CVE-2021-43718 | An Authentication Bypass vulnerability exists in EPSON EH-TW5350 EPSON ... | check |
| CVE-2022-23538 | github.com/sylabs/scs-library-client is the Go client for the Singular ... | check details, might as well affect golang-github-apptainer-container-library-client |
| CVE-2022-50942 | Incinga Web 2.8.2 contains a client-side cross-site scripting vulnerab ... | check status upstream |
| CVE-2023-26044 | react/http is an event-driven, streaming HTTP client and server implem ... | check, is embedded inicinga-php-thirdparty, icingaweb2-module-reactbundle possibly affected |
| CVE-2023-47268 | In libslic3r/GCode/PostProcessor.cpp in Prusa PrusaSlicer through 2.6. ... | check |
| CVE-2023-49316 | In Math/BinaryField.php in phpseclib 3 before 3.0.34, excessively larg ... | check if affecting ldap-account-manager or unused path |
| CVE-2023-50251 | php-svg-lib is an SVG file parsing / rendering library. Prior to versi ... | check, other packages are embedding the library: civicrm, icinga-php-thirdparty and icingaweb2 to be checked |
| CVE-2023-50252 | php-svg-lib is an SVG file parsing / rendering library. Prior to versi ... | check, other packages are embedding the library: civicrm, icinga-php-thirdparty and icingaweb2 to be checked |
| CVE-2023-50262 | Dompdf is an HTML to PDF converter for PHP. When parsing SVG images Do ... | check sources embedding php-dompdf if affected |
| CVE-2024-7708 | For requests that have a body, but reading the body may end up in read ... | check |
| CVE-2024-13942 | Secure BootROM of RK3588s SoC is vulnerable to a time-of-check to time ... | check |
| CVE-2024-14045 | A weakness has been identified in OpenBoxes up to 0.9.2. This vulnerab ... | check |
| CVE-2024-14046 | A security vulnerability has been detected in OpenBoxes up to 0.9.1. T ... | check |
| CVE-2024-22420 | JupyterLab is an extensible environment for interactive and reproducib ... | check completeness, src:jupyter-notebook? |
| CVE-2024-22421 | JupyterLab is an extensible environment for interactive and reproducib ... | check completeness, src:jupyter-notebook? |
| CVE-2024-47091 | Privilege escalation in the mk_mysql agent plugin on Windows in Checkm ... | check |
| CVE-2024-54192 | An issue inTcpreplay v4.5.1 allows a local attacker to cause a denial ... | check |
| CVE-2024-58376 | Renovate versions 37.158.0 before 37.199.0 contain a command injection ... | check |
| CVE-2025-0041 | Uncontrolled search paths in the Vitis\u2122 Embedded Single File Down ... | check |
| CVE-2025-0046 | Incorrect directory permissions could allow a local user to escalate t ... | check |
| CVE-2025-4382 | A flaw was found in systems utilizing LUKS-encrypted disks with GRUB c ... | double check if vulnerability only considered present after grub_is_cli_disabled is introduced |
| CVE-2025-6499 | A vulnerability classified as problematic was found in vstakhov libucl ... | check if impacts security wise rspamd, which embeds libucl and uses it a compile time |
| CVE-2025-8671 | A mismatch caused by client-triggered server-sent stream resets betwee ... | check, some projects will assign own CVEs and should then be covered under that specific CVE instead |
| CVE-2025-8941 | A flaw was found in linux-pam. The pam_namespace module may improperly ... | check likely RedHat specific incomplete fix for CVE-2025-6020, but asked to pinpoint incomplete fixes |
| CVE-2025-9210 | Missing signature validation in JSON Web Tokens in Otalio Ship Propert ... | check |
| CVE-2025-9211 | Unescaped stored values in application security page in Otalio Ship Pr ... | check |
| CVE-2025-11010 | A vulnerability has been found in vstakhov libucl up to 0.9.2. Affecte ... | check if impacts security wise rspamd, which embeds libucl and uses it a compile time |
| CVE-2025-11147 | Reflected cross-site scripting (XSS) in Apt-Cacher-NG v3.2.1. The vuln ... | clarifying with reporter and Eduard Bloch on the issue. |
| CVE-2025-14575 | An Uncontrolled Search Path Element vulnerability in the OpenSSL TLS b ... | check |
| CVE-2025-14600 | An insecure deserialization vulnerability in vsDesk allows a remote at ... | check |
| CVE-2025-14603 | The application component processes user-supplied parameters insecurel ... | check |
| CVE-2025-15569 | A flaw has been found in Artifex MuPDF up to 1.26.1 on Windows. The im ... | check |
| CVE-2025-27621 | UpTrain is an open-source platform to evaluate and improve generative ... | check |
| CVE-2025-27770 | UpTrain is an open-source platform to evaluate and improve generative ... | check |
| CVE-2025-27771 | UpTrain is an open-source platform to evaluate and improve generative ... | check |
| CVE-2025-27772 | UpTrain is an open-source platform to evaluate and improve generative ... | check |
| CVE-2025-31114 | Fooocus is an image generating software. In versions 2.5.5 and prior, ... | check |
| CVE-2025-31356 | Insufficient verification of data authenticity for some Intel(R) Trust ... | check |
| CVE-2025-33221 | NVIDIA Display Driver for Windows and Linux contains a vulnerability i ... | check |
| CVE-2025-35987 | Omission of security-relevant information for some Intel(R) Software G ... | check |
| CVE-2025-41769 | The device's PROFINET service is affected by a buffer overflow vulnera ... | check |
| CVE-2025-41770 | An unauthenticated denial-of-service vulnerability in the device's PLC ... | check |
| CVE-2025-41771 | An authenticated attacker with low privileges can access an endpoint i ... | check |
| CVE-2025-48505 | Weak permissions in the Vitis\u2122 Unified installation path on local ... | check |
| CVE-2025-58064 | CKEditor 5 is a modern JavaScript rich-text editor with an MVC archite ... | check |
| CVE-2025-59319 | CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to certif ... | check |
| CVE-2025-59320 | CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 stores TPM2.0 s ... | check |
| CVE-2025-59321 | CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 contains a defa ... | check |
| CVE-2025-59322 | CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to proper ... | check |
| CVE-2025-59323 | CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to valida ... | check |
| CVE-2025-59324 | CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to proper ... | check |
| CVE-2025-59325 | CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to encryp ... | check |
| CVE-2025-59326 | CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to enforc ... | check |
| CVE-2025-59327 | In CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4, bootxsa.efi ... | check |
| CVE-2025-60796 | phpPgAdmin 7.13.0 and earlier contains multiple cross-site scripting ( ... | check, possibly not reported upstream |
| CVE-2025-60797 | phpPgAdmin 7.13.0 and earlier contains a SQL injection vulnerability i ... | check, possibly not reported upstream |
| CVE-2025-60798 | phpPgAdmin 7.13.0 and earlier contains a SQL injection vulnerability i ... | check, possibly not reported upstream |
| CVE-2025-60799 | phpPgAdmin 7.13.0 and earlier contains an incorrect access control vul ... | check, possibly not reported upstream |
| CVE-2025-61261 | A reflected cross-site scripting (XSS) vulnerability in CKeditor v46.1 ... | check |
| CVE-2025-61970 | Weak permissions in the Vitis\u2122 Unified installation path on local ... | check |
| CVE-2025-61982 | An arbitrary code execution vulnerability exists in the Code Stream di ... | check upstream status |
| CVE-2025-63913 | An issue was discovered in OpenSBI 1.3 allowing attackers to cause a d ... | check |
| CVE-2025-66578 | xmlseclibs is a library written in PHP for working with XML Encryption ... | check |
| CVE-2025-67108 | eProsima Fast-DDS v3.3 was discovered to contain improper validation f ... | check https://gist.github.com/lkloliver/81b5d5a8328d712dbfd497bf11dbe913, unclear if reported upstream |
| CVE-2025-69534 | Python-Markdown version 3.8 contain a vulnerability where malformed HT ... | Asking whether it really needs a backport: https://bugs.debian.org/1131896 |
| CVE-2025-69720 | The infocmp command-line tool in ncurses before 6.5-20251213 has a sta ... | check upstream status |
| CVE-2025-69969 | A lack of authentication and authorization mechanisms in the Bluetooth ... | check |
| CVE-2025-70887 | An issue in ralphje Signify before v.0.9.2 allows a remote attacker to ... | check |
| CVE-2025-71405 | chi versions before v5.2.2 contain an open redirect vulnerability in t ... | check |
| CVE-2026-0708 | A flaw was found in libucl. A remote attacker could exploit this by pr ... | check if impacts security wise rspamd, which embeds libucl and uses it a compile time |
| CVE-2026-1703 | When pip is installing and extracting a maliciously crafted wheel arch ... | check as well pipenv |
| CVE-2026-4833 | A weakness has been identified in Orc discount up to 3.0.1.2. This iss ... | check libtext-markdown-discount-perl, ruby-rdiscount, cantor, embedding discount; check if security impact present |
| CVE-2026-5224 | Cleartext storage of sensitive information vulnerability in Kriptok Cr ... | check |
| CVE-2026-5422 | A path traversal vulnerability exists in jupyter-server version 2.17.0 ... | CNA contacted responsible for this CVE entry as this seems to be a duplicate of CVE-2026-35397 |
| CVE-2026-6657 | A vulnerability in jupyter-server versions 1.12.0 through 2.17.0 allow ... | CNA contacted responsible for this CVE entry as this seems to be a duplicate of CVE-2026-40110 |
| CVE-2026-7701 | A security vulnerability has been detected in Telegram Desktop up to 6 ... | check upstream reports |
| CVE-2026-7790 | Uncontrolled Resource Consumption vulnerability in ninenines cowlib (c ... | check if embedded copy in rabbitmq-server is problematic |
| CVE-2026-8851 | SOGo versions 5.12.7 and prior contains a SQL injection vulnerability ... | check correctness |
| CVE-2026-8863 | Multiple Microsoft-sigend UEFI SHIM bootloaders are vulnerable to Secu ... | check |
| CVE-2026-10037 | A sandbox escape vulnerability exists in the OpenJDK packages provided ... | check |
| CVE-2026-10051 | In Eclipse Jetty, a first HTTP/1.1 request with trailers causes the se ... | check, jetty9 might not be affected as not explicitly mentioned in the GhSA and still supported |
| CVE-2026-10527 | Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21, 11.8.x <= 1 ... | check |
| CVE-2026-10754 | Pega Platform versions 8.5.0 through 25.1.2 are affected by an imprope ... | check |
| CVE-2026-11325 | Description Cloudflare was recently notified by external researcher ... | check |
| CVE-2026-11751 | A vulnerability has been identified in armeria-xds versions prior to 1 ... | check |
| CVE-2026-11817 | This vulnerability only affects Grafana stacks configured with multipl ... | check |
| CVE-2026-12624 | Vault\u2019s ACL policy engine did not consistently enforce a wildcard ... | check |
| CVE-2026-13133 | A vulnerability has been identified in LineInst.exe (LINE for Windows) ... | check |
| CVE-2026-13206 | Improper neutralization of special elements used in an OS command ('OS ... | check |
| CVE-2026-13500 | A weakness has been identified in antlr ANTLR4 up to 4.13.2. Affected ... | check upstream reporting and status |
| CVE-2026-13501 | A security vulnerability has been detected in antlr ANTLR4 up to 4.13. ... | check upstream reporting and status |
| CVE-2026-13502 | A flaw has been found in antlr ANTLR4 up to 4.13.2. This affects the f ... | check upstream reporting and status |
| CVE-2026-13503 | A vulnerability was detected in antlr ANTLR4 up to 4.13.2. Affected by ... | check upstream reporting and status |
| CVE-2026-14304 | In Eclipse Accessibility Tools Framework (ACTF) versions up to 1.6.0 ( ... | check |
| CVE-2026-14564 | Insufficiently Protected Credentials vulnerability in Innotim Software ... | check |
| CVE-2026-14587 | Neo4j's Bolt modern handshake decoder treats an overlong capability bi ... | check |
| CVE-2026-15585 | Improper Limitation of a Pathname to a Restricted Directory ('Path Tra ... | check |
| CVE-2026-15779 | A flaw was found in samba's pam_winbind. When mkhomedir is enabled, pa ... | check if Red Hat specific |
| CVE-2026-15816 | A flaw was found in dracut. The die() error-handling function writes i ... | check |
| CVE-2026-16019 | Improper neutralization of special elements used in an SQL command ('S ... | check |
| CVE-2026-16309 | Authorization bypass through User-Controlled key vulnerability in Neti ... | check |
| CVE-2026-16493 | A flaw was found in ansible-core. The _extract_collection_from_git() f ... | check upstream details |
| CVE-2026-16566 | | check upstream report and status on fix |
| CVE-2026-16732 | fastify is a fast and low overhead web framework for Node.js. Impact: ... | check |
| CVE-2026-17106 | The tar extraction routines in moby/go-archive (Unpack, UnpackLayer, U ... | check |
| CVE-2026-17183 | An authenticated user with permission to create or edit alert rules ca ... | check |
| CVE-2026-17523 | A flaw was found in the Linux kernel in net/can/bcm.c in can: bcm, whe ... | wait, contacted CNAs (Red Hat and Linux Kernel CNA) for proper reassignment |
| CVE-2026-18358 | A flaw was found in gnome-remote-desktop as shipped in Red Hat Enterpr ... | does not affect an upstream version, but need to check if still only Red Hat specific, check details RH bug |
| CVE-2026-18430 | HumHub 1.18.4 contains a stored cross-site scripting vulnerability in ... | check |
| CVE-2026-18497 | A heap-buffer-overflow vulnerability exists in the nothings stb TrueTy ... | check, missing upstream details |
| CVE-2026-18504 | fastify is a fast and low overhead web framework for Node.js. Versions ... | check |
| CVE-2026-18526 | HumHub Community Edition 1.18.4 and 1.18.4-pl1 contain a stored Cross- ... | check |
| CVE-2026-18534 | ArcSearch for iOS versions prior to 1.48.0 could keep the address bar ... | check |
| CVE-2026-18674 | On a Kong Mesh global control plane, resources received over the zone- ... | check |
| CVE-2026-18756 | HumHub Community Edition 1.18.4 contains a reflected cross-site script ... | check |
| CVE-2026-18874 | A flaw was found in volsync-addon-controller. This vulnerability allow ... | check |
| CVE-2026-18929 | Carbone is vulnerable to Denial of Service due to lack of protection a ... | check |
| CVE-2026-19198 | Akaunting 3.1.21 contains an authenticated improper authorization vuln ... | check |
| CVE-2026-19447 | Improper neutralization of input during web page generation ('cross-si ... | check |
| CVE-2026-19500 | The Entries component in Brainstorm Force SureForms version, less than ... | check |
| CVE-2026-19501 | CSV export functionality in Brainstorm Force SureForms version, <= 2.1 ... | check |
| CVE-2026-19589 | Packer up to 1.15.4 is vulnerable to an issue in the third-party plugi ... | check |
| CVE-2026-19670 | Malcolm's nginx Lua role-based access control (RBAC) layer decides whe ... | check |
| CVE-2026-19671 | Malcolm's upload-processing pipeline (scripts/safe-extract.py) enforce ... | check |
| CVE-2026-19672 | The tarfile module's tar and data extraction filters created director ... | check |
| CVE-2026-19869 | @neo4j/graphqlfrom5.2.0until the patched versions fails to enforce fie ... | check |
| CVE-2026-20030 | As part of Cisco's ongoing commitment to proactive security and produc ... | check |
| CVE-2026-20177 | A vulnerability in the handling of management plane packets by Cisco I ... | check |
| CVE-2026-20231 | As part of Cisco's ongoing commitment to proactive security and produc ... | check |
| CVE-2026-20232 | A vulnerability in the web-based management interface of Cisco Industr ... | check |
| CVE-2026-20314 | A vulnerability in Cisco Packaged Contact Center Enterprise (Packaged ... | check |
| CVE-2026-20315 | As part of Cisco's ongoing commitment to proactive security and produc ... | check |
| CVE-2026-20317 | As part of Cisco's ongoing commitment to proactive security and produc ... | check |
| CVE-2026-20318 | As part of Cisco's ongoing commitment to proactive security and produc ... | check |
| CVE-2026-20319 | As part of Cisco's ongoing commitment to proactive security and produc ... | check |
| CVE-2026-20327 | A vulnerability in the web-based management interface of Cisco Unified ... | check |
| CVE-2026-20337 | A vulnerability in the zip archive parser of ClamAV could allow an una ... | check |
| CVE-2026-20338 | A vulnerability in the zip archive parser of ClamAV could allow an una ... | check |
| CVE-2026-20357 | As part of Cisco's ongoing commitment to proactive security and produc ... | check |
| CVE-2026-20358 | As part of Cisco's ongoing commitment to proactive security and produc ... | check |
| CVE-2026-20359 | As part of Cisco's ongoing commitment to proactive security and produc ... | check |
| CVE-2026-20776 | Improper conditions check for some Intel(R) PROSet/Wireless WiFi Softw ... | check |
| CVE-2026-22739 | Vulnerability in Spring Cloud when substituting the profile parameter ... | check |
| CVE-2026-22752 | Authentication bypass by primary weakness vulnerability in Spring Secu ... | check |
| CVE-2026-23479 | Redis is an in-memory data structure store. In redis-server from 7.2.0 ... | check redict and valkey |
| CVE-2026-23631 | Redis is an in-memory data structure store. In all versions of redis-s ... | check redict and valkey |
| CVE-2026-24182 | NVIDIA Display Driver for Windows and Linux contains a vulnerability w ... | check |
| CVE-2026-24187 | NVIDIA Display Driver for Linux contains a vulnerability where an atta ... | check |
| CVE-2026-24190 | NVIDIA Display Driver for Windows and Linux contains a vulnerability i ... | check |
| CVE-2026-24192 | NVIDIA Display Driver for Linux contains a vulnerability where an atta ... | check |
| CVE-2026-24193 | NVIDIA Display Driver for Windows and Linux contains a vulnerability w ... | check |
| CVE-2026-24194 | NVIDIA Display Driver for Linux contains a vulnerability in a kernel m ... | check |
| CVE-2026-24195 | NVIDIA Display Driver for Linux contains a vulnerability in UVM, where ... | check |
| CVE-2026-24196 | NVIDIA Display Driver for Linux contains a vulnerability where a user ... | check |
| CVE-2026-24197 | NVIDIA Display Driver for Linux contains a vulnerability in the Multi- ... | check |
| CVE-2026-24198 | NVIDIA GPU Display Driver for Linux contains a vulnerability where an ... | check |
| CVE-2026-24199 | NVIDIA Display Driver for Linux contains a vulnerability in a kernel m ... | check |
| CVE-2026-25243 | Redis is an in-memory data structure store. In versions of redis-serve ... | check redict and valkey |
| CVE-2026-27970 | Angular is a development platform for building mobile and desktop web ... | check status for older versions |
| CVE-2026-28343 | CKEditor 5 is a modern JavaScript rich-text editor with an MVC archite ... | check |
| CVE-2026-28687 | ImageMagick is free and open-source software used for editing and mani ... | For imagemagick6 superseded by fix inside jumbo patch for CVE-2026-28686, first patch was incomplete |
| CVE-2026-28687 | ImageMagick is free and open-source software used for editing and mani ... | Fixed by: https://github.com/ImageMagick/ImageMagick6/commit/6a602fb36f181a0089848344a3b0d79fc6155a2b (6.9.13-41) |
| CVE-2026-28688 | ImageMagick is free and open-source software used for editing and mani ... | For imagemagick6 by fix inside jumbo patch for CVE-2026-28686, first patch was incomplete |
| CVE-2026-28688 | ImageMagick is free and open-source software used for editing and mani ... | Fixed by: https://github.com/ImageMagick/ImageMagick6/commit/6a602fb36f181a0089848344a3b0d79fc6155a2b (6.9.13-41) |
| CVE-2026-29022 | dr_libs dr_wav.h version 0.14.4 and earlier (fixed in commit 8a7258c) ... | qtads, dosbox-x, roc-toolkit, octave-ltfat, faudio bundle a copy, check security impact |
| CVE-2026-29035 | CivetWeb (commit 4a4f0c95) contains a heap and stack buffer overflow v ... | check details upstream |
| CVE-2026-29036 | cJSON versions 1.5.0 through 1.7.19 contain an incorrectly-resolved na ... | check, report upstream status |
| CVE-2026-30250 | Cross-site scripting vulnerability in the user documentation field in ... | check |
| CVE-2026-30478 | A Dynamic-link Library Injection vulnerability in GatewayGeo MapServer ... | check |
| CVE-2026-30479 | A Dynamic-link Library Injection vulnerability in OSGeo Project MapSer ... | check |
| CVE-2026-31053 | A double free vulnerability exists in librz/bin/format/le/le.c in the ... | check |
| CVE-2026-32148 | Insufficient Verification of Data Authenticity vulnerability in hexpm ... | check |
| CVE-2026-32313 | xmlseclibs is a library written in PHP for working with XML Encryption ... | check |
| CVE-2026-32600 | xml-security is a library that implements XML signatures and encryptio ... | check |
| CVE-2026-32635 | Angular is a development platform for building mobile and desktop web ... | check status for older versions |
| CVE-2026-34240 | JOSE is a Javascript Object Signing and Encryption (JOSE) library. Pri ... | check |
| CVE-2026-34398 | FreeCAD is a free and open-source multiplatform 3D parametric modeler. ... | check |
| CVE-2026-34399 | FreeCAD is a free and open-source multiplatform 3D parametric modeler. ... | check |
| CVE-2026-34789 | FreeCAD is a free and open-source multiplatform 3D parametric modeler. ... | check |
| CVE-2026-36499 | A missing upper-bound check in the udpif_set_threads() function of Ope ... | check, unclear status/validity |
| CVE-2026-38165 | A Server-Side Template Injection (SSTI) vulnerability in the Velocity ... | check |
| CVE-2026-39178 | A SQL injection vulnerability in SOGo before 5.12.7 allows authenticat ... | CVE-2026-39178 and CVE-2026-39179 are duplicates of CVE-2026-46445 and CVE-2026-46446, CNA contacted |
| CVE-2026-39179 | A SQL injection vulnerability in SOGo before 5.12.7 allows authenticat ... | CVE-2026-39178 and CVE-2026-39179 are duplicates of CVE-2026-46445 and CVE-2026-46446, CNA contacted |
| CVE-2026-39254 | Buffer Overflow vulnerability in SteelSeries GG (macOS) v.107.0.0 allo ... | check |
| CVE-2026-39255 | Buffer Overflow vulnerability in SteelSeries GG (macOS) v.107.0.0 allo ... | check |
| CVE-2026-39860 | Nix is a package manager for Linux and other Unix systems. A bug in th ... | check, potentially affecting guix if same issue in backporting fix for CVE-2024-2729 |
| CVE-2026-40033 | FreeRDP before 3.26.0 contains a heap-buffer-overflow vulnerability in ... | unclear fixing commit references, incorrect reference in CVE entry? |
| CVE-2026-41424 | Wazuh is a free and open source platform used for threat prevention, d ... | check |
| CVE-2026-41889 | pgx is a PostgreSQL driver and toolkit for Go. Prior to version 5.9.2, ... | check the other golang-github-jackc-pgx* sources |
| CVE-2026-41921 | Koha before 26.05.02, 25.11.07, and 25.05.13 contains a stored cross-s ... | check |
| CVE-2026-42162 | Mahara before 25.04.5 and 26.04.0 is vulnerable to artefacts being acc ... | check |
| CVE-2026-42163 | Mahara before 25.04.5 and 26.04.0 is vulnerable to unauthorized access ... | check |
| CVE-2026-42164 | Mahara before 25.04.5 and 26.04.0 is vulnerable in the Text block/sect ... | check |
| CVE-2026-42199 | Grid is a data structure grid for rust. From version 0.17.0 to before ... | check |
| CVE-2026-42308 | Pillow is a Python imaging library. Prior to version 12.2.0, if a font ... | research fixing commit(s), maybe https://github.com/python-pillow/Pillow/pull/9518/changes |
| CVE-2026-42503 | gopls by default communicates via pipe. However, -port and -listen fla ... | check impact on golang-golang-x-tools |
| CVE-2026-43627 | llama.cpp builds b1283 through b9058 contain an integer overflow vulne ... | check |
| CVE-2026-43628 | llama.cpp builds b3978 through b9058 contain an integer underflow and ... | check |
| CVE-2026-43629 | llama.cpp builds b4882 through b9058 contain a heap buffer overflow vu ... | check |
| CVE-2026-43631 | llama.cpp builds b7492 through the latest b9060 contains a use-after-f ... | check |
| CVE-2026-43632 | llama.cpp builds b7492 through the latest b9060 contains a use-after-f ... | check |
| CVE-2026-43829 | Full details and mitigation steps are currently restricted and will be ... | check |
| CVE-2026-43830 | Full details and mitigation steps are currently restricted and will be ... | check |
| CVE-2026-43831 | Full details and mitigation steps are currently restricted and will be ... | check |
| CVE-2026-43832 | Full details and mitigation steps are currently restricted and will be ... | check |
| CVE-2026-43833 | Full details and mitigation steps are currently restricted and will be ... | check |
| CVE-2026-43971 | Improper Encoding or Escaping of Output vulnerability in ninenines cow ... | check |
| CVE-2026-44252 | Wazuh is a free and open source platform used for threat prevention, d ... | check |
| CVE-2026-44253 | Wazuh is a free and open source platform used for threat prevention, d ... | check |
| CVE-2026-44254 | Wazuh is a free and open source platform used for threat prevention, d ... | check |
| CVE-2026-44255 | Wazuh is a free and open source platform used for threat prevention, d ... | check |
| CVE-2026-44256 | Wazuh is a free and open source platform used for threat prevention, d ... | check |
| CVE-2026-44472 | Saleor is an e-commerce platform. From 2.10.0rc1 until 3.21.67, 3.22.6 ... | check |
| CVE-2026-44829 | Gotenberg is a Docker-powered stateless API for PDF files. In 8.32.0 a ... | check |
| CVE-2026-44845 | JumpServer is an open source bastion host and an operation and mainten ... | check |
| CVE-2026-44846 | JumpServer is an open source bastion host and an operation and mainten ... | check |
| CVE-2026-44901 | Wazuh is a free and open source platform used for threat prevention, d ... | check |
| CVE-2026-44933 | `PluginScript` attempts to `chroot` the plugin to the `repoManagerRoot ... | check |
| CVE-2026-45272 | MyBooks is an enhanced and easy-to-use personal ebook management web s ... | check |
| CVE-2026-45273 | MyBooks is an ebook management web server also known as Talebook. In 3 ... | check |
| CVE-2026-45274 | MyBooks is anebook management web server also known as Talebook. In 3. ... | check |
| CVE-2026-45388 | In OCaml-TLS before 2.1.0, the client implementation does insufficient ... | check |
| CVE-2026-45389 | In OCaml-TLS before 2.1.0, the server implementation does insufficient ... | check |
| CVE-2026-45390 | In OCaml-tar before 3.4.0, a crafted archive with ../ path segments in ... | check |
| CVE-2026-45733 | Trilium Notes is a cross-platform, hierarchical note taking applicatio ... | check |
| CVE-2026-45741 | Gotenberg is a Docker-powered stateless API for PDF files. In 8.32.0 a ... | check |
| CVE-2026-45742 | Gotenberg is a Docker-powered stateless API for PDF files. From 8.10.0 ... | check |
| CVE-2026-45790 | Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior t ... | check |
| CVE-2026-45791 | Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior t ... | check |
| CVE-2026-45798 | Wazuh is a free and open source platform used for threat prevention, d ... | check |
| CVE-2026-46343 | Wazuh is a free and open source platform used for threat prevention, d ... | check |
| CVE-2026-46727 | An issue was discovered in Ruby 4 before 4.0.5. A race condition leadi ... | check |
| CVE-2026-47699 | Confidential Containers Guest Components provides guest tools and comp ... | check |
| CVE-2026-47719 | FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) softwa ... | check |
| CVE-2026-47720 | FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) softwa ... | check |
| CVE-2026-47721 | FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) softwa ... | check |
| CVE-2026-48024 | Wazuh is a free and open source platform used for threat prevention, d ... | check |
| CVE-2026-48162 | Wazuh is a free and open source platform used for threat prevention, d ... | check |
| CVE-2026-48744 | Saleor is an e-commerce platform. From 3.14.67 until 3.21.67, 3.22.63, ... | check |
| CVE-2026-48796 | CefSharp provides .NET bindings for the Chromium Embedded Framework fo ... | check |
| CVE-2026-48798 | SSH.NET is a Secure Shell (SSH) library for .NET. In 2025.1.0 and earl ... | check |
| CVE-2026-48809 | python-engineio is a Python implementation of the Engine.IO realtime c ... | checking upstream commit fixing issue, confusing infomation advisory claims both 4.13.2 and 4.13.5 to fix issue |
| CVE-2026-49221 | Vvveb is a powerful and easy to use CMS with page builder to build web ... | check |
| CVE-2026-49222 | Vvveb is a powerful and easy to use CMS with page builder to build web ... | check |
| CVE-2026-49223 | Vvveb is a powerful and easy to use CMS with page builder to build web ... | check |
| CVE-2026-49224 | Vvveb is a powerful and easy to use CMS with page builder to build web ... | check |
| CVE-2026-49225 | Vvveb is a powerful and easy to use CMS with page builder to build web ... | check |
| CVE-2026-49226 | Vvveb is a powerful and easy to use CMS with page builder to build web ... | check |
| CVE-2026-49227 | Vvveb is a powerful and easy to use CMS with page builder to build web ... | check |
| CVE-2026-49228 | Vvveb is a powerful and easy to use CMS with page builder to build web ... | check |
| CVE-2026-49253 | electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VN ... | check |
| CVE-2026-49255 | electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VN ... | check |
| CVE-2026-49283 | The SimpleSAMLphp SAML2 library is a PHP library for SAML2 related fun ... | check |
| CVE-2026-49289 | The SimpleSAMLphp SAML2 library is a PHP library for SAML2 related fun ... | check |
| CVE-2026-49392 | Wazuh is a free and open source platform used for threat prevention, d ... | check |
| CVE-2026-49415 | During execve(2) of a SUID binary, the new virtual address space is in ... | check |
| CVE-2026-49418 | When msync(MS_INVALIDATE) is called on a mapping of an unmanaged devic ... | check |
| CVE-2026-49419 | When the JAIL_AT_DESC flag is specified, kern_jail_set() and kern_jail ... | check |
| CVE-2026-49420 | The RTSP handler in libalias rewrote outgoing packets into a fixed-len ... | check |
| CVE-2026-49421 | The kernel function that implements unlinkat(2) and funlinkat(2) valid ... | check |
| CVE-2026-49422 | The RACK setsockopt(2) handler drops the connection lock in order to c ... | check |
| CVE-2026-49423 | When building the iovec array for a received TLS 1.2 CBC record, ktls_ ... | check |
| CVE-2026-49424 | The Linux waitid() implementation translates a FreeBSD siginfo_t struc ... | check |
| CVE-2026-49425 | The compat32 kevent() handler translates a 64-bit kevent struct into a ... | check |
| CVE-2026-49426 | When auditing a system call executed via ptrace(PT_SC_REMOTE), the ker ... | check |
| CVE-2026-49427 | Pages belonging to largepage shared memory objects were not explicitly ... | check |
| CVE-2026-49428 | Certain system calls, such open(2) with the O_TRUNC flag set, and fspa ... | check |
| CVE-2026-49429 | The ZFS_IOC_USERSPACE_MANY ioctl, used by zfs-userspace(8), truncated ... | check |
| CVE-2026-49430 | The ZFS_IOC_RECV_NEW ioctl, in the heal receive path, similarly trunca ... | check |
| CVE-2026-49431 | The ZFS_IOC_SET_PROP ioctl, used by zfs-set(8), incorrectly validated ... | check |
| CVE-2026-49441 | Wazuh is a free and open source platform used for threat prevention, d ... | check |
| CVE-2026-49870 | Snipe-IT is an IT asset/license management system. Prior to 8.6.1, POS ... | check |
| CVE-2026-49976 | Snipe-IT is an IT asset/license management system. Prior to 8.6.1, a u ... | check |
| CVE-2026-50126 | Adaguc-server is an open source geographical information system to vis ... | check |
| CVE-2026-50138 | goshs is a SimpleHTTPServer written in Go. Prior to version 2.1.0, whe ... | check |
| CVE-2026-50139 | goshs is a SimpleHTTPServer written in Go. Prior to version 2.1.0, `Sh ... | check |
| CVE-2026-50143 | The Apify MCP server enables AI agents to extract data from websites u ... | check |
| CVE-2026-50161 | libre is a generic library for real-time communications with asynchron ... | check |
| CVE-2026-50167 | Kurrier is a modern, self-hosted workspace for email, calendar, contac ... | check |
| CVE-2026-50173 | Flow-Like is a platform for building end-to-end use cases. Prior to ve ... | check |
| CVE-2026-50186 | 4gaBoards is a boards system for realtime project management. Prior to ... | check |
| CVE-2026-50187 | Oh My Zsh is a community-driven framework for managing Zsh configurati ... | check |
| CVE-2026-50191 | 4gaBoards is a boards system for realtime project management. Prior to ... | check |
| CVE-2026-50550 | Snipe-IT is an IT asset/license management system. Prior to 8.5.0, a u ... | check |
| CVE-2026-50575 | BetterDesk is a remote desktop management solution. BetterDesk version ... | check |
| CVE-2026-50576 | ePA 3.x Integration implements the authorization workflow and writes M ... | check |
| CVE-2026-50577 | ePA 3.x Integration implements the authorization workflow and writes M ... | check |
| CVE-2026-50578 | ePA 3.x Integration implements the authorization workflow and writes M ... | check |
| CVE-2026-50719 | The Ingenic T41, and probably also T32, T40, and A1 SoC boot ROMs pars ... | check |
| CVE-2026-50720 | The Ingenic T31 SoC boot ROM flash-boot verification path compares onl ... | check |
| CVE-2026-51366 | SQL Injection vulnerability in Bottinelli Informatica Vedo Suite v.1.2 ... | check |
| CVE-2026-51367 | An issue in Bottinelli Informatica Vedo Suite v.1.2.5 allows a remote ... | check |
| CVE-2026-51400 | An issue in Vim Project v9.2.0389 and earlier allows a local attacker ... | check, possibly not reported upstream, only reporter reference in github gist |
| CVE-2026-51401 | An issue in Vim Project v9.2.0389 and earlier allows a local attacker ... | check, possibly not reported upstream, only reporter reference in github gist |
| CVE-2026-51977 | An issue in Trueview T18061 WiFi 3MP Robot Pan-Tilt Security Camera Ve ... | check |
| CVE-2026-52480 | An issue in SJRC F11 SJ-GPS-PRO firmware build 2019-09-17 allows a rem ... | check |
| CVE-2026-52481 | An issue in SJRC F11 SJ-GPS-PRO firmware build 2019-09-17 allows a rem ... | check |
| CVE-2026-52606 | A reflected cross-site scripting (XSS) vulnerability in reportico-web ... | check |
| CVE-2026-52607 | A directory traversal vulnerability in reportico-web <= 8.1.0 allows r ... | check |
| CVE-2026-52608 | An incorrect access control vulnerability in reportico-web <= 8.1.0 al ... | check |
| CVE-2026-52609 | A reflected cross-site scripting (XSS) vulnerability in reportico-web ... | check |
| CVE-2026-52610 | An arbitrary file write/directory traversal vulnerability in reportico ... | check |
| CVE-2026-52723 | ePA 3.x Integration implements the authorization workflow and writes M ... | check |
| CVE-2026-52731 | ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, an att ... | check |
| CVE-2026-52732 | ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, one un ... | check |
| CVE-2026-52733 | ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, a natu ... | check |
| CVE-2026-52734 | ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, an una ... | check |
| CVE-2026-52735 | ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, Zebra ... | check |
| CVE-2026-52736 | ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, a remo ... | check |
| CVE-2026-52737 | ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, a mali ... | check |
| CVE-2026-52738 | ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, a cons ... | check |
| CVE-2026-52739 | ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, a mali ... | check |
| CVE-2026-52792 | Algernon is a small self-contained pure-Go web server. Prior to 1.17.9 ... | check |
| CVE-2026-52793 | Froxlor is open source server administration software. Prior to 2.3.7, ... | check |
| CVE-2026-52817 | Linuxfabrik Monitoring Plugins provides monitoring plugins for Icinga, ... | check |
| CVE-2026-52829 | ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, an una ... | check |
| CVE-2026-52834 | jxl-oxide is a pure Rust implementation of a JPEG XL decoder. Prior to ... | check |
| CVE-2026-52854 | Maps is a MediaWiki extension that enables visualization of geographic ... | check |
| CVE-2026-52872 | Streambert is a cross-platform Electron Desktop App to stream and down ... | check |
| CVE-2026-52873 | Streambert is a cross-platform Electron Desktop App to stream and down ... | check |
| CVE-2026-52875 | Streambert is a cross-platform Electron Desktop App to stream and down ... | check |
| CVE-2026-52876 | Streambert is a cross-platform Electron Desktop App to stream and down ... | check |
| CVE-2026-52877 | Streambert is a cross-platform Electron Desktop App to stream and down ... | check |
| CVE-2026-52886 | Notepad++ is a free and open-source source code editor. Prior to 8.9.7 ... | check |
| CVE-2026-53451 | Ground Station is a browser-based suite for satellite tracking, SDR re ... | check |
| CVE-2026-53452 | Ground Station is a browser-based suite for satellite tracking, SDR re ... | check |
| CVE-2026-53453 | Blueprint Studio is a VS Code-like file editor for Home Assistant conf ... | check |
| CVE-2026-53454 | Blueprint Studio is a VS Code-like file editor for Home Assistant conf ... | check |
| CVE-2026-53455 | Blueprint Studio is a VS Code-like file editor for Home Assistant conf ... | check |
| CVE-2026-53456 | Blueprint Studio is a VS Code-like file editor for Home Assistant conf ... | check |
| CVE-2026-53457 | Blueprint Studio is a VS Code-like file editor for Home Assistant conf ... | check |
| CVE-2026-53458 | Blueprint Studio is a VS Code-like file editor for Home Assistant conf ... | check |
| CVE-2026-53533 | aiosmtplib is an asynchronous SMTP client for use with asyncio. Prior ... | check |
| CVE-2026-53654 | Grav is a file-based Web platform. Prior to 3.8.5, the Login plugin tw ... | check |
| CVE-2026-53759 | linuxfabrik-lib provides Python modules for database access, caching, ... | check |
| CVE-2026-53958 | 4gaBoards is a boards system for realtime project management. Prior to ... | check |
| CVE-2026-53959 | 4gaBoards is a boards system for realtime project management. Prior to ... | check |
| CVE-2026-54336 | JumpServer is an open source bastion host and an operation and mainten ... | check |
| CVE-2026-54347 | Froxlor is open source server administration software. Prior to 2.3.8, ... | check |
| CVE-2026-54348 | Froxlor is open source server administration software. Prior to 2.3.8, ... | check |
| CVE-2026-54356 | Budibase is an open-source low-code platform. Prior to 3.41.3, POST /a ... | check |
| CVE-2026-54543 | Froxlor is open source server administration software. Prior to 2.3.8, ... | check |
| CVE-2026-54552 | sh provides Python process launching. Prior to 2.2.4, the _uid option ... | check |
| CVE-2026-54570 | AngleSharp is a .NET library for parsing angle bracket based hyper-tex ... | check |
| CVE-2026-54730 | authentik is an open-source identity provider. Prior to 2026.2.6 and 2 ... | check |
| CVE-2026-54758 | Notepad++ is a free and open-source source code editor. Prior to 8.9.7 ... | check |
| CVE-2026-55106 | authentik is an open-source identity provider. Prior to 2026.2.6 and 2 ... | check |
| CVE-2026-55223 | c3p0 is a JDBC Connection pooling library. In versions prior to 0.14.0 ... | check if that is an issue with the packaged version |
| CVE-2026-55426 | linuxfabrik-lib provides Python modules for database access, caching, ... | check |
| CVE-2026-55482 | Snipe-IT is an IT asset/license management system. Prior to 8.4.1, a n ... | check |
| CVE-2026-55483 | Snipe-IT is an IT asset/license management system. Prior to 8.6.0, an ... | check |
| CVE-2026-55519 | Snipe-IT is an IT asset/license management system. Prior to 8.4.1, an ... | check |
| CVE-2026-55593 | Froxlor is open source server administration software. Prior to 2.3.8, ... | check |
| CVE-2026-55643 | Snipe-IT is an IT asset/license management system. Prior to 8.6.3, a c ... | check |
| CVE-2026-55694 | Snipe-IT is an IT asset/license management system. Prior to 8.6.3, a r ... | check |
| CVE-2026-55703 | Snipe-IT is an IT asset/license management system. Prior to 8.6.3, any ... | check |
| CVE-2026-55839 | Kestra is an open-source, event-driven orchestration platform. Prior t ... | check |
| CVE-2026-56677 | 9Router is an AI router & token saver. In 0.5.4 and earlier, the POST ... | check |
| CVE-2026-56684 | Valkey is a distributed key-value database. Prior to 7.2.14, 8.0.10, 8 ... | check |
| CVE-2026-56816 | Netty is a network application framework for development of protocol s ... | check, potentially only in 4.2.y series |
| CVE-2026-56818 | Netty is an asynchronous, event-driven network application framework. ... | check missing upstream GHSA |
| CVE-2026-57233 | Notepad++ is a free and open-source source code editor. Prior to 8.9.7 ... | check |
| CVE-2026-57485 | Stirling-PDF is a locally hosted web application that facilitates vari ... | check |
| CVE-2026-57580 | authentik is an open-source identity provider. Prior to 2026.2.6 and 2 ... | check |
| CVE-2026-57826 | An issue was discovered in openHiTLS 0.2.0 through 0.3.2. In the X.509 ... | check |
| CVE-2026-57862 | Kanboard 1.2.52 and prior contains a server-side request forgery vulne ... | check upstream report |
| CVE-2026-58081 | Several encoding modules, including HZ, UTF-7, VIQR, and ZW, did not p ... | check |
| CVE-2026-58082 | The ISO-2022 encoding module used a stack buffer sized to MB_LEN_MAX ( ... | check |
| CVE-2026-58083 | While the kernel was copying knotes during fork, a knote with a timer- ... | check |
| CVE-2026-58084 | To retrieve the previous timer value, the kernel calls realtimer_getti ... | check |
| CVE-2026-58085 | After dispatching a decrypt operation to OCF and receiving the result, ... | check |
| CVE-2026-58086 | As an inadvertent side effect of an unrelated code change, PRIV_KTRACE ... | check |
| CVE-2026-58087 | The GETALL and SETALL commands in semctl(2) recorded the number of sem ... | check |
| CVE-2026-58088 | The ELF core dump code counted the number of dumpable VM map entries, ... | check |
| CVE-2026-59825 | Mastodon is a free, open-source social network server based on Activit ... | check |
| CVE-2026-59940 | Seroval facilitates JS value stringification, including complex struct ... | check |
| CVE-2026-59949 | yawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.1, JN ... | check |
| CVE-2026-60392 | Vulnerability in the Oracle Outside In Technology product of Oracle Fu ... | check |
| CVE-2026-60412 | Vulnerability in the Oracle Outside In Technology product of Oracle Fu ... | check |
| CVE-2026-60413 | Vulnerability in the Oracle Outside In Technology product of Oracle Fu ... | check |
| CVE-2026-60414 | Vulnerability in the Oracle Outside In Technology product of Oracle Fu ... | check |
| CVE-2026-60758 | Vulnerability in the Siebel Artificial Intelligence product of Oracle ... | check |
| CVE-2026-60822 | Vulnerability in the Oracle Enterprise Manager for Systems Infrastruct ... | check |
| CVE-2026-60860 | Vulnerability in the Service Delivery Platform product of Oracle Fusio ... | check |
| CVE-2026-60861 | Vulnerability in the Service Delivery Platform product of Oracle Fusio ... | check |
| CVE-2026-60865 | Vulnerability in the Service Delivery Platform product of Oracle Fusio ... | check |
| CVE-2026-60866 | Vulnerability in the Service Delivery Platform product of Oracle Fusio ... | check |
| CVE-2026-60956 | Vulnerability in the JD Edwards EnterpriseOne US Payroll product of Or ... | check |
| CVE-2026-61002 | Vulnerability in the Oracle SOA Suite product of Oracle Fusion Middlew ... | check |
| CVE-2026-61003 | Vulnerability in the Oracle Managed File Transfer product of Oracle Fu ... | check |
| CVE-2026-61198 | Vulnerability in the Oracle Learning Management product of Oracle E-Bu ... | check |
| CVE-2026-61241 | Vulnerability in the Oracle Internet Directory product of Oracle Fusio ... | check |
| CVE-2026-61248 | Vulnerability in the Oracle Internet Directory product of Oracle Fusio ... | check |
| CVE-2026-61258 | Vulnerability in the Oracle Internet Directory product of Oracle Fusio ... | check |
| CVE-2026-61265 | Vulnerability in the JD Edwards EnterpriseOne Orchestrator product of ... | check |
| CVE-2026-61270 | Vulnerability in the JD Edwards EnterpriseOne Orchestrator product of ... | check |
| CVE-2026-61319 | Vulnerability in the Oracle U.S. Federal Financials product of Oracle ... | check |
| CVE-2026-61331 | Vulnerability in the Oracle Financials Common Modules product of Oracl ... | check |
| CVE-2026-61518 | ISPConfig contains an authenticated SQL injection vulnerability in the ... | check |
| CVE-2026-61574 | authentik is an open-source identity provider. Prior to 2026.2.6 and 2 ... | check |
| CVE-2026-61607 | Grav API Plugin is a RESTful API for Grav CMS that provides full headl ... | check |
| CVE-2026-61666 | websocket-driver is a WebSocket protocol handler with pluggable I/O. P ... | check |
| CVE-2026-61690 | Grav is a file-based Web platform. Prior to 2.0.1, Grav ZipArchiver::e ... | check |
| CVE-2026-61696 | Forem is open source software for building communities. In versions be ... | check |
| CVE-2026-61807 | Snipe-IT is an IT asset/license management system. Prior to 8.6.2, a s ... | check |
| CVE-2026-61842 | Grav is a file-based Web platform. Prior to 2.0.2, the Grav Twig conte ... | check |
| CVE-2026-62291 | libheif is a HEIF and AVIF file format decoder and encoder. In 1.23.0 ... | check |
| CVE-2026-62357 | Dragonfly is an in-memory data store built for modern application work ... | check |
| CVE-2026-62377 | libheif is a HEIF and AVIF file format decoder and encoder. In 1.23.0 ... | check |
| CVE-2026-62448 | Vulnerability in the Oracle Email Center product of Oracle E-Business ... | check |
| CVE-2026-62449 | Vulnerability in the Oracle Work in Process product of Oracle E-Busine ... | check |
| CVE-2026-62450 | Vulnerability in the Oracle Flow Manufacturing product of Oracle E-Bus ... | check |
| CVE-2026-62458 | Vulnerability in the Oracle Work in Process product of Oracle E-Busine ... | check |
| CVE-2026-62462 | Vulnerability in the Oracle Work in Process product of Oracle E-Busine ... | check |
| CVE-2026-62475 | Vulnerability in the Oracle Shipping Execution product of Oracle E-Bus ... | check |
| CVE-2026-62585 | Vulnerability in the Siebel CRM Administration product of Oracle Siebe ... | check |
| CVE-2026-62586 | Vulnerability in the Siebel CRM Administration product of Oracle Siebe ... | check |
| CVE-2026-62587 | Vulnerability in the Siebel CRM Administration product of Oracle Siebe ... | check |
| CVE-2026-62599 | Vulnerability in the Oracle Trading Community product of Oracle E-Busi ... | check |
| CVE-2026-62600 | Vulnerability in the Oracle Sales product of Oracle E-Business Suite ( ... | check |
| CVE-2026-62601 | Vulnerability in the Oracle Sales product of Oracle E-Business Suite ( ... | check |
| CVE-2026-62605 | Vulnerability in the Oracle Partner Management product of Oracle E-Bus ... | check |
| CVE-2026-62607 | Vulnerability in the Oracle Customer Care product of Oracle E-Business ... | check |
| CVE-2026-62666 | Grav API Plugin is a RESTful API for Grav CMS that provides full headl ... | check |
| CVE-2026-62667 | Grav API Plugin is a RESTful API for Grav CMS that provides full headl ... | check |
| CVE-2026-62668 | Grav API Plugin is a RESTful API for Grav CMS that provides full headl ... | check |
| CVE-2026-62669 | Grav Login Plugin adds login, basic ACL, and session wide messages to ... | check |
| CVE-2026-62670 | Grav Flex Objects Plugin allows you to build custom collections of obj ... | check |
| CVE-2026-62671 | Grav Login Plugin adds login, basic ACL, and session wide messages to ... | check |
| CVE-2026-62672 | Grav is a file-based Web platform. Prior to 2.0.4, Grav allowlists the ... | check |
| CVE-2026-62673 | Grav is a file-based Web platform. Prior to 2.0.4, the Grav .htaccess ... | check |
| CVE-2026-62680 | Orval generates type-safe JavaScript clients in TypeScript from OpenAP ... | check |
| CVE-2026-62681 | Orval generates type-safe JavaScript clients in TypeScript from OpenAP ... | check |
| CVE-2026-62682 | Orval generates type-safe JavaScript clients in TypeScript from OpenAP ... | check |
| CVE-2026-62684 | File Browser is a file managing interface for uploading, deleting, pre ... | check |
| CVE-2026-62988 | Froxlor is open source server administration software. From 2.3.7 unti ... | check |
| CVE-2026-63117 | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior ... | check |
| CVE-2026-63178 | Onyx is an open-source AI platform. Prior to 4.3.0, Onyx Enterprise Ed ... | check |
| CVE-2026-63328 | Trivy is a security scanner. Prior to 0.72.0, plugin manifest metadata ... | check |
| CVE-2026-63407 | Grav API Plugin is a RESTful API for Grav CMS that provides full headl ... | check |
| CVE-2026-63408 | Grav API Plugin is a RESTful API for Grav CMS that provides full headl ... | check |
| CVE-2026-63409 | Deskflow is a keyboard and mouse sharing app. From 1.17.0 until contin ... | check |
| CVE-2026-63632 | Open Neural Network Exchange (ONNX) is an open standard for machine le ... | check |
| CVE-2026-63633 | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior ... | check |
| CVE-2026-63639 | Valkey is a distributed key-value database. Prior to 7.2.14, 8.0.10, 8 ... | check |
| CVE-2026-63640 | MagicMirror\xb2 is an open source modular smart mirror platform. Prior ... | check |
| CVE-2026-63641 | MagicMirror\xb2 is an open source modular smart mirror platform. Prior ... | check |
| CVE-2026-63642 | MagicMirror\xb2 is an open source modular smart mirror platform. Prior ... | check |
| CVE-2026-63643 | MagicMirror\xb2 is an open source modular smart mirror platform. Prior ... | check |
| CVE-2026-63652 | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior ... | check |
| CVE-2026-64611 | A flaw was found in libcupsfilters. The cfIEEE1284NormalizeMakeModel() ... | check use in embedded cups, cups-filters |
| CVE-2026-65609 | nnn is vulnerable to Out-of-Bound write vulnerability.Due to lack of v ... | check |
| CVE-2026-65610 | nnn stores homelen variable as uchar_t, which can only represent value ... | check |
| CVE-2026-65611 | nnn does not sanitize the path variable. An attacker can createa direc ... | check |
| CVE-2026-65612 | nnn does not sanitize the filename variable. An attacker can place a f ... | check |
| CVE-2026-67846 | Berkeley Out-of-Order Machine (BOOM) commit 5223e44cfeb26f41380057a2eb ... | check |
| CVE-2026-70622 | tar-rs versions 0.4.11 through 0.4.46 contain a symlink escape vulnera ... | check, unclear if reported upstream |
| CVE-2026-71261 | dr_libs dr_wav.h (all versions through current master) contains an int ... | check |
| CVE-2026-71263 | The LINUXTCP port of FreeModbus contains an off-by-one bounds check in ... | check |
| CVE-2026-71266 | tinyobjloader-c's tinyobj_parse_and_index_mtl_file (tinyobj_loader_c.h ... | check |
| CVE-2026-71287 | Cacti's sanitize_sql_column (lib/functions.php) sanitizes user-supplie ... | check, assigned from "Turan Security" CNA without further detailed references |
| CVE-2026-71290 | Improper TLS hostname verification vulnerability in Apache HttpCompone ... | check, claimed to affect only version 5.2 onwards |
| CVE-2026-71437 | Mermaid is a JavaScript tool that uses Markdown-inspired text to creat ... | check introducing commit for further assessment |
| CVE-2026-71439 | Mermaid is a JavaScript tool that uses Markdown-inspired text to creat ... | check introducing commit, might then be only 11.6.0 and above. |
| CVE-2026-72556 | A remote code execution vulnerability in ZoneMinder 1.39.17 allows any ... | check, another CVE assigned by "Turan Security" CNA without providing details |
| CVE-2026-75032 | A flaw was found in BlueZ. Insufficient validation of packet length fi ... | check, Red Hat bugzilla entry (only source) contains no information |
| CVE-2026-75926 | Hugo 0.161.0 placed the Node asset pipelines behind the Node.js permis ... | double check introducing commit, as CVE entry claims only starting 0.162.0 |
| CVE-2026-76014 | A vulnerability has been found in BusyBox up to 1.30.1. This vulnerabi ... | check details, reported as issue on github mirror |
| TEMP-1142597-FFA22A | GHSA-68ff-gq39-pqjm: relay: authentication bypass with the "plain" password hash algorithm | check, GHSA-68ff-gq39-pqjm claims >= 4.3.0 but potentially since v2.9-rc1 |