| Bug | Description | Note |
|---|
| CVE-2016-1584 | In all versions of Unity8 a running but not active application on a la ... | check proper tracking update |
| CVE-2016-20096 | Linknat VOS3000 and VOS2009 through version 2.1.2.0 contain an unauthe ... | check |
| CVE-2018-25246 | Wikipedia 12.0 contains a denial of service vulnerability that allows ... | check |
| CVE-2018-25305 | librsvg2-bin 2.40.13 contains a buffer overflow vulnerability that all ... | check |
| CVE-2018-25306 | PDFunite 0.41.0 contains a buffer overflow vulnerability that allows l ... | check |
| CVE-2019-25485 | R 3.4.4 on Windows x64 contains a buffer overflow vulnerability in the ... | check |
| CVE-2019-25683 | FileZilla 3.40.0 contains a denial of service vulnerability in the loc ... | check |
| CVE-2021-27137 | An issue was discovered in router/upnp/src/ssdp.c in DD-WRT before 457 ... | check |
| CVE-2022-23538 | github.com/sylabs/scs-library-client is the Go client for the Singular ... | check details, might as well affect golang-github-apptainer-container-library-client |
| CVE-2022-50942 | Incinga Web 2.8.2 contains a client-side cross-site scripting vulnerab ... | check status upstream |
| CVE-2023-26044 | react/http is an event-driven, streaming HTTP client and server implem ... | check, is embedded inicinga-php-thirdparty, icingaweb2-module-reactbundle possibly affected |
| CVE-2023-47268 | In libslic3r/GCode/PostProcessor.cpp in Prusa PrusaSlicer through 2.6. ... | check |
| CVE-2023-49316 | In Math/BinaryField.php in phpseclib 3 before 3.0.34, excessively larg ... | check if affecting ldap-account-manager or unused path |
| CVE-2023-49899 | An unauthenticated remote attacker canexecute any command on the affec ... | check |
| CVE-2023-49900 | An unauthenticated remote attacker is able to perform remote code exec ... | check |
| CVE-2023-50251 | php-svg-lib is an SVG file parsing / rendering library. Prior to versi ... | check, other packages are embedding the library: civicrm, icinga-php-thirdparty and icingaweb2 to be checked |
| CVE-2023-50252 | php-svg-lib is an SVG file parsing / rendering library. Prior to versi ... | check, other packages are embedding the library: civicrm, icinga-php-thirdparty and icingaweb2 to be checked |
| CVE-2023-50262 | Dompdf is an HTML to PDF converter for PHP. When parsing SVG images Do ... | check sources embedding php-dompdf if affected |
| CVE-2024-7708 | For requests that have a body, but reading the body may end up in read ... | check |
| CVE-2024-22420 | JupyterLab is an extensible environment for interactive and reproducib ... | check completeness, src:jupyter-notebook? |
| CVE-2024-22421 | JupyterLab is an extensible environment for interactive and reproducib ... | check completeness, src:jupyter-notebook? |
| CVE-2024-32385 | An issue in Kerlink Kerlink Wirnet iStation 868 KerOS v.4.3.3_20200803 ... | check |
| CVE-2024-32386 | Directory traversal vulnerability in Kerlink Kerlink Wirnet iStation 8 ... | check |
| CVE-2024-32387 | An issue in Kerlink Kerlink Wirnet iStation 868 KerOS v.4.3.3_20200803 ... | check |
| CVE-2024-32389 | Buffer Overflow vulnerability in Kerlink Kerlink Wirnet iStation 868 K ... | check |
| CVE-2024-34268 | EQ-3 Eqiva CC-RT-BLE Bluetooth Smart Radiator Thermostat Firmware up t ... | check |
| CVE-2024-47091 | Privilege escalation in the mk_mysql agent plugin on Windows in Checkm ... | check |
| CVE-2024-54192 | An issue inTcpreplay v4.5.1 allows a local attacker to cause a denial ... | check |
| CVE-2024-58360 | stoatchat versions before 0.7.8 fail to enforce account creation restr ... | check |
| CVE-2025-3110 | OpenVPN Access Server 2.7.2 through 3.1.0 accepts bare line-feed seque ... | check |
| CVE-2025-4382 | A flaw was found in systems utilizing LUKS-encrypted disks with GRUB c ... | double check if vulnerability only considered present after grub_is_cli_disabled is introduced |
| CVE-2025-6499 | A vulnerability classified as problematic was found in vstakhov libucl ... | check if impacts security wise rspamd, which embeds libucl and uses it a compile time |
| CVE-2025-8412 | A Buffer Copy without Checking Size of Input ('Classic Buffer Overflow ... | check |
| CVE-2025-8671 | A mismatch caused by client-triggered server-sent stream resets betwee ... | check, some projects will assign own CVEs and should then be covered under that specific CVE instead |
| CVE-2025-8941 | A flaw was found in linux-pam. The pam_namespace module may improperly ... | check likely RedHat specific incomplete fix for CVE-2025-6020, but asked to pinpoint incomplete fixes |
| CVE-2025-11010 | A vulnerability has been found in vstakhov libucl up to 0.9.2. Affecte ... | check if impacts security wise rspamd, which embeds libucl and uses it a compile time |
| CVE-2025-11147 | Reflected cross-site scripting (XSS) in Apt-Cacher-NG v3.2.1. The vuln ... | clarifying with reporter and Eduard Bloch on the issue. |
| CVE-2025-14575 | An Uncontrolled Search Path Element vulnerability in the OpenSSL TLS b ... | check |
| CVE-2025-15569 | A flaw has been found in Artifex MuPDF up to 1.26.1 on Windows. The im ... | check |
| CVE-2025-15667 | A vulnerability was determined in GPAC up to 2.5-DEV. This vulnerabili ... | check |
| CVE-2025-15668 | A vulnerability was identified in GPAC up to b40ce70f5. This issue aff ... | check |
| CVE-2025-30007 | HestiaCP before 1.9.5 contains an authenticated OS command injection v ... | check |
| CVE-2025-30008 | HestiaCP before 1.9.5 contains a stored cross-site scripting vulnerabi ... | check |
| CVE-2025-32781 | Apollo is a reliable configuration management system suitable for micr ... | check |
| CVE-2025-33221 | NVIDIA Display Driver for Windows and Linux contains a vulnerability i ... | check |
| CVE-2025-45422 | Incorrect access control in Proximus b-box v8c.725A allows authenticat ... | check |
| CVE-2025-45868 | LogicalDOC Enterprise up to and for v9.1.1 is vulnerable to blind SQL ... | check |
| CVE-2025-45870 | LogicalDOC Enterprise up to and for v9.1.1 is vulnerable to Local File ... | check |
| CVE-2025-51677 | An issue was discovered in openRISC OR1200 commit 83ac6b. An output mi ... | check |
| CVE-2025-51678 | An issue was discovered in RISC-V PicoRV32 commit 87c89a. A mismatch i ... | check |
| CVE-2025-56361 | A reachable assertion vulnerability exists in the Matter SDK (connecte ... | check |
| CVE-2025-56362 | A reachable assertion vulnerability exists in the Matter SDK (connecte ... | check |
| CVE-2025-56363 | A null pointer dereference vulnerability exists in the Matter SDK (con ... | check |
| CVE-2025-56364 | A use of uninitialized value vulnerability exists in the Matter SDK (c ... | check |
| CVE-2025-56365 | A reachable assertion vulnerability exists in the Matter SDK (connecte ... | check |
| CVE-2025-58064 | CKEditor 5 is a modern JavaScript rich-text editor with an MVC archite ... | check |
| CVE-2025-60357 | AhnLab EPP Management v1.0.14.32-6249 was discovered to contain a NoSQ ... | check |
| CVE-2025-60796 | phpPgAdmin 7.13.0 and earlier contains multiple cross-site scripting ( ... | check, possibly not reported upstream |
| CVE-2025-60797 | phpPgAdmin 7.13.0 and earlier contains a SQL injection vulnerability i ... | check, possibly not reported upstream |
| CVE-2025-60798 | phpPgAdmin 7.13.0 and earlier contains a SQL injection vulnerability i ... | check, possibly not reported upstream |
| CVE-2025-60799 | phpPgAdmin 7.13.0 and earlier contains an incorrect access control vul ... | check, possibly not reported upstream |
| CVE-2025-61261 | A reflected cross-site scripting (XSS) vulnerability in CKeditor v46.1 ... | check |
| CVE-2025-61982 | An arbitrary code execution vulnerability exists in the Code Stream di ... | check upstream status |
| CVE-2025-65720 | An issue in Open Source GPT Researcher v3.3.7 allows attackers to exec ... | check |
| CVE-2025-66390 | In Microsoft Azure API Management through 2025-10-17, when self-servic ... | check |
| CVE-2025-66578 | xmlseclibs is a library written in PHP for working with XML Encryption ... | check |
| CVE-2025-67108 | eProsima Fast-DDS v3.3 was discovered to contain improper validation f ... | check https://gist.github.com/lkloliver/81b5d5a8328d712dbfd497bf11dbe913, unclear if reported upstream |
| CVE-2025-68640 | The Apple Find My backend service through 2025-12-17 allows an attacke ... | check |
| CVE-2025-69534 | Python-Markdown version 3.8 contain a vulnerability where malformed HT ... | Asking whether it really needs a backport: https://bugs.debian.org/1131896 |
| CVE-2025-69720 | The infocmp command-line tool in ncurses before 6.5-20251213 has a sta ... | check upstream status |
| CVE-2025-69969 | A lack of authentication and authorization mechanisms in the Bluetooth ... | check |
| CVE-2025-70796 | An unauthenticated path traversal vulnerability exists in the web mana ... | check |
| CVE-2025-70887 | An issue in ralphje Signify before v.0.9.2 allows a remote attacker to ... | check |
| CVE-2025-71377 | stoatchat (delta) versions before 20250210-1 (0.8.2) contain a logic e ... | check |
| CVE-2025-71388 | stoatchat (delta/Revolt) versions from 20241213-1 before 20250210-1 al ... | check |
| CVE-2026-0708 | A flaw was found in libucl. A remote attacker could exploit this by pr ... | check if impacts security wise rspamd, which embeds libucl and uses it a compile time |
| CVE-2026-1703 | When pip is installing and extracting a maliciously crafted wheel arch ... | check as well pipenv |
| CVE-2026-2395 | Improper neutralization of special elements used in an SQL command ('S ... | check |
| CVE-2026-2406 | Authorization bypass through User-Controlled key vulnerability in Univ ... | check |
| CVE-2026-4773 | Improper validation of specified type of input vulnerability in Magars ... | check |
| CVE-2026-4833 | A weakness has been identified in Orc discount up to 3.0.1.2. This iss ... | check libtext-markdown-discount-perl, ruby-rdiscount, cantor, embedding discount; check if security impact present |
| CVE-2026-7701 | A security vulnerability has been detected in Telegram Desktop up to 6 ... | check upstream reports |
| CVE-2026-7790 | Uncontrolled Resource Consumption vulnerability in ninenines cowlib (c ... | check if embedded copy in rabbitmq-server is problematic |
| CVE-2026-8484 | A heap buffer overflow vulnerability exists in the Jansi JNI "ioctl()" ... | double-check source packages, as there is not much details from cert.pl post |
| CVE-2026-8851 | SOGo versions 5.12.7 and prior contains a SQL injection vulnerability ... | check correctness |
| CVE-2026-8863 | Multiple Microsoft-sigend UEFI SHIM bootloaders are vulnerable to Secu ... | check |
| CVE-2026-10037 | A sandbox escape vulnerability exists in the OpenJDK packages provided ... | check |
| CVE-2026-10051 | In Eclipse Jetty, a first HTTP/1.1 request with trailers causes the se ... | check |
| CVE-2026-10097 | wolfSSL's AVX2-optimized ML-KEM implementation (mlkem_cmp_avx2) compar ... | check |
| CVE-2026-10098 | OCSP CertID serial-number length-confusion in wolfSSL_OCSP_resp_find_s ... | check |
| CVE-2026-10130 | QueryWeaver contains an authentication bypass vulnerability that allow ... | check |
| CVE-2026-10512 | The X25519 x86_64 assembly implementation fails to clear the most sign ... | check |
| CVE-2026-10592 | Certificates with wildcard DNS SANs (e.g. *.example.com) bypassed CA n ... | check |
| CVE-2026-10706 | In Adalo\u2019s no-code app builder, (Versions 1 and 2) the attackers ... | check |
| CVE-2026-10708 | This vulnerability enables large\u2011scale data harvesting without re ... | check |
| CVE-2026-11310 | X.509 trust-chain bypass in the OpenSSL compatibility certificate veri ... | check |
| CVE-2026-11321 | The DataInjection plugin for GLPI 2.15.6 (GLPI 11 builds) concatenates ... | check |
| CVE-2026-11386 | An input validation and injection vulnerability exists in Canonical ub ... | check |
| CVE-2026-11404 | Cesanta Mongoose before 7.22 contains an out-of-bounds read in the bui ... | check |
| CVE-2026-11703 | Missing SNI/ALPN binding on stateful (session-ID) resumption, which pr ... | check |
| CVE-2026-11763 | Authorization bypass through User-Controlled key vulnerability in Gis ... | check |
| CVE-2026-11876 | In zenml-io/zenml version 0.94.2, the `GET /api/v1/stack-deployment/st ... | check |
| CVE-2026-11889 | SALTO ProAccess Space software using the tenancy feature / logical pa ... | check |
| CVE-2026-11944 | openSIS Classic 9.3 contains an authenticated path traversal vulnerabi ... | check |
| CVE-2026-11999 | X.509 trust-chain bypass (path-depth exhaustion) in the OpenSSL compat ... | check |
| CVE-2026-12080 | A flaw was found in the QEMU Guest Agent (qga). A local unprivileged u ... | check |
| CVE-2026-12228 | A stored cross-site scripting (XSS) vulnerability exists in the `POST ... | check |
| CVE-2026-12340 | Out-of-bounds heap read during SM2/SM3 certificate signature verificat ... | check |
| CVE-2026-12341 | This vulnerability impacts all versions of IdentityIQ and allows an un ... | check |
| CVE-2026-12379 | An Open Redirect vulnerability (CWE-601) exists in the OAuth/OIDC auth ... | check |
| CVE-2026-12382 | A flaw was found in the AAP Gateway Envoy proxy configuration. The non ... | check |
| CVE-2026-12391 | An insecure symlink following vulnerability exists in Canonical ubuntu ... | check |
| CVE-2026-12478 | The fix for CVE-2026-0716 (commit 6ff7ef0, libsoup 3.6.6) placed the i ... | check |
| CVE-2026-12482 | A vulnerability in keras-team/keras version 3.12.0 allows an attacker ... | check |
| CVE-2026-12484 | A vulnerability in keras-team/keras version 3.15.0 allows unsafe deser ... | check |
| CVE-2026-12523 | Summary Cloudflare quiche's HTTP/3 layer was discovered to be vulne ... | check |
| CVE-2026-12547 | SoupAuthManager caches proxy authentication credentials without scopin ... | check |
| CVE-2026-12548 | A heap out-of-bounds read flaw was found in libsoup. When parsing mult ... | check |
| CVE-2026-12590 | Impact: In body-parser versions prior to 1.20.6 (1.x line) and 2.3.0 ( ... | check |
| CVE-2026-12593 | The implementation of an internalandundocumentedDashboardAPI endpoint( ... | check |
| CVE-2026-12606 | Eclipse Grizzly in versions before 5.0.2, cannot properly parse the tr ... | check |
| CVE-2026-12616 | The /v1/upload/sbom endpoint extracts the iss claim from the attacker- ... | check |
| CVE-2026-12681 | Improper Validation of Specified Index, Position, or Offset in Input v ... | check |
| CVE-2026-12691 | Missing authentication for critical function vulnerability in Vimesoft ... | check |
| CVE-2026-12692 | Unverified password change vulnerability in Vimesoft Inc. Enterprise V ... | check |
| CVE-2026-12693 | Authorization bypass through User-Controlled key vulnerability in Vime ... | check |
| CVE-2026-12694 | Missing Authorization vulnerability in Vimesoft Inc. Enterprise Video ... | check |
| CVE-2026-12701 | A path traversal vulnerability was found in pulpcore. The relative_pat ... | check |
| CVE-2026-12707 | Summary Cloudflare quiche was discovered to be vulnerable to memory ... | check |
| CVE-2026-12715 | Missing Authorization in Google Cloud Firebase Studio versions prior t ... | check |
| CVE-2026-13380 | VSee Clinic 7.1.26 and VSee Clinic API 1.3.0 exposes cleartext SFTP cr ... | check |
| CVE-2026-13381 | VSee Clinic 7.1.26 and API1.3.0contain an Insecure Direct Object Refer ... | check |
| CVE-2026-13500 | A weakness has been identified in antlr ANTLR4 up to 4.13.2. Affected ... | check upstream reporting and status |
| CVE-2026-13501 | A security vulnerability has been detected in antlr ANTLR4 up to 4.13. ... | check upstream reporting and status |
| CVE-2026-13502 | A flaw has been found in antlr ANTLR4 up to 4.13.2. This affects the f ... | check upstream reporting and status |
| CVE-2026-13503 | A vulnerability was detected in antlr ANTLR4 up to 4.13.2. Affected by ... | check upstream reporting and status |
| CVE-2026-13724 | Client-Side Enforcement of Server-Side Security vulnerability in Gobit ... | check |
| CVE-2026-14191 | An out-of-bounds heap write exists in the RAR5 recovery-volume (.rev) ... | check |
| CVE-2026-14448 | An high privileged remote attacker can exploit an authenticated OS com ... | check |
| CVE-2026-14551 | The servereye client (also known as sensorhub, technically ClientAgent ... | check |
| CVE-2026-14906 | Pages with malicious titles could potentially allow saved PDF content ... | check |
| CVE-2026-14985 | The Analog Way Picturall Quad Compact Mark II version 3.5.8, contains ... | check |
| CVE-2026-15034 | A vulnerability has been found in flask-dashboard Flask-MonitoringDash ... | check |
| CVE-2026-15063 | A flaw was found in the gorch service template, which is part of the t ... | check |
| CVE-2026-15308 | The incremental HTML parser (html.parser.HTMLParser) allows for CPU de ... | check |
| CVE-2026-15588 | A denial-of-service and resource exhaustion vulnerability exists withi ... | check |
| CVE-2026-15690 | A vulnerability was identified in open62541 up to 1.5.5. Affected by t ... | check |
| CVE-2026-15709 | A flaw was found in libsoup's WebSocket implementation when using the ... | check |
| CVE-2026-15711 | A vulnerability was found in libsoup's WebSocket frame parsing impleme ... | check |
| CVE-2026-15712 | A heap buffer over-read vulnerability was discovered in libsoup's (ver ... | check |
| CVE-2026-15713 | A vulnerability was found in libsoup's HTTP/2 protocol implementation. ... | check |
| CVE-2026-15714 | An out-of-bounds read vulnerability was found in libsoup's multipart p ... | check |
| CVE-2026-15779 | A flaw was found in samba's pam_winbind. When mkhomedir is enabled, pa ... | check if Red Hat specific |
| CVE-2026-15788 | BuildKit's cache mount source= selector on Windows Container on Window ... | check |
| CVE-2026-15789 | A custom client can produce such an upload request to the BuildKit dae ... | check |
| CVE-2026-15791 | A crafted message in the BuildKit low-level build API can be used to r ... | check |
| CVE-2026-15792 | A malicious BuildKit client or frontend could craft a request that cou ... | check |
| CVE-2026-15793 | BuildKit custom frontends or clients using the raw low-level API can s ... | check |
| CVE-2026-15811 | A vulnerability was found in kronosnet's (version <=1.34) cryptographi ... | check |
| CVE-2026-15812 | A vulnerability was found in the internal Access Control List (ACL) su ... | check |
| CVE-2026-15813 | A vulnerability was found in the network packet de-fragmentation engin ... | check |
| CVE-2026-15829 | A SQL injection (CWE-89) and security boundary bypass (CWE-863) vulner ... | check |
| CVE-2026-16118 | A flaw was found in xdgmime. A heap-based buffer overflow can be trigg ... | check |
| CVE-2026-16157 | Duplicati v2.3.0.1 backup software gives Authenticated Users MODIFY pe ... | check |
| CVE-2026-16232 | An authentication bypass vulnerability in the Check Point SmartConsole ... | check |
| CVE-2026-16254 | A flaw was found in claircore's apk package scanner. Malformed package ... | check |
| CVE-2026-16270 | Open Mercato does not validate regex rules. An attacker with privilege ... | check |
| CVE-2026-16454 | InEclipse hawkBitversions 1.0.3 and prior, a privilege escalation vuln ... | check |
| CVE-2026-16473 | A flaw was found in the sbc library (BlueZ SBC codec). An off-by-one e ... | check |
| CVE-2026-16488 | A vulnerability was determined in QUSETIONS MiniCode-Python 0.1.0. Thi ... | check |
| CVE-2026-16489 | A vulnerability was identified in jsforce up to 3.10.16. This issue af ... | check |
| CVE-2026-16492 | A weakness has been identified in umijs umi up to 4.6.63. The affected ... | check |
| CVE-2026-16493 | A flaw was found in ansible-core. The _extract_collection_from_git() f ... | check upstream details |
| CVE-2026-16517 | A signed integer overflow vulnerability was found in libarchive's ZIP ... | check |
| CVE-2026-16544 | A flaw was found in AWX. The websocket event consumer performs RBAC au ... | check |
| CVE-2026-16551 | Denial-of-Service in Thinkst Applied Research OpenCanary (MongoDB modu ... | check |
| CVE-2026-16552 | A flaw was found in systemd-tmpfiles. When processing a tmpfiles.d con ... | check |
| CVE-2026-16560 | A heap-buffer-overflow flaw was found in Directory Server (389-ds-base ... | check |
| CVE-2026-16606 | A vulnerability in Fujitsu Software Linux openFT andFujitsu Software O ... | check |
| CVE-2026-16607 | A vulnerability in Fujitsu Software Linux openFT andFujitsu Software O ... | check |
| CVE-2026-16615 | A flaw was found in librest. The PKCE implementation for OAuth authori ... | check |
| CVE-2026-16624 | Cal.com OSS ships lacks authorization on webhook teamId creation, allo ... | check |
| CVE-2026-21953 | Vulnerability in the Oracle Retail Xstore Point of Service product of ... | check |
| CVE-2026-21954 | Vulnerability in the Oracle Retail Xstore Point of Service product of ... | check |
| CVE-2026-22739 | Vulnerability in Spring Cloud when substituting the profile parameter ... | check |
| CVE-2026-22752 | Authentication bypass by primary weakness vulnerability in Spring Secu ... | check |
| CVE-2026-23479 | Redis is an in-memory data structure store. In redis-server from 7.2.0 ... | check redict and valkey |
| CVE-2026-23631 | Redis is an in-memory data structure store. In all versions of redis-s ... | check redict and valkey |
| CVE-2026-24182 | NVIDIA Display Driver for Windows and Linux contains a vulnerability w ... | check |
| CVE-2026-24187 | NVIDIA Display Driver for Linux contains a vulnerability where an atta ... | check |
| CVE-2026-24190 | NVIDIA Display Driver for Windows and Linux contains a vulnerability i ... | check |
| CVE-2026-24191 | NVIDIA Display Driver for Windows contains a vulnerability where an at ... | check |
| CVE-2026-24192 | NVIDIA Display Driver for Linux contains a vulnerability where an atta ... | check |
| CVE-2026-24193 | NVIDIA Display Driver for Windows and Linux contains a vulnerability w ... | check |
| CVE-2026-24194 | NVIDIA Display Driver for Linux contains a vulnerability in a kernel m ... | check |
| CVE-2026-24195 | NVIDIA Display Driver for Linux contains a vulnerability in UVM, where ... | check |
| CVE-2026-24196 | NVIDIA Display Driver for Linux contains a vulnerability where a user ... | check |
| CVE-2026-24197 | NVIDIA Display Driver for Linux contains a vulnerability in the Multi- ... | check |
| CVE-2026-24198 | NVIDIA GPU Display Driver for Linux contains a vulnerability where an ... | check |
| CVE-2026-24199 | NVIDIA Display Driver for Linux contains a vulnerability in a kernel m ... | check |
| CVE-2026-24232 | NVIDIA Tranformers4Rec contains a vulnerability where an attacker coul ... | check |
| CVE-2026-25243 | Redis is an in-memory data structure store. In versions of redis-serve ... | check redict and valkey |
| CVE-2026-25701 | An Insecure Temporary File vulnerability in openSUSE sdbootutil allows ... | check |
| CVE-2026-25702 | A Improper Access Control vulnerability in the kernel of SUSE SUSE Lin ... | check |
| CVE-2026-26197 | HDF5 is a high-performance library and a file format specification tha ... | check, isolate upstream change, might only be relevant for 2.0.0 onwards |
| CVE-2026-26199 | HDF5 is a high-performance library and a file format specification tha ... | isolate fixing commit |
| CVE-2026-27586 | Caddy is an extensible server platform that uses TLS by default. Prior ... | check, introducing version |
| CVE-2026-27704 | The Dart and Flutter SDKs provide software development kits for the Da ... | check |
| CVE-2026-27738 | The Angular SSR is a server-rise rendering tool for Angular applicatio ... | check |
| CVE-2026-27739 | The Angular SSR is a server-rise rendering tool for Angular applicatio ... | check |
| CVE-2026-27970 | Angular is a development platform for building mobile and desktop web ... | check status for older versions |
| CVE-2026-28343 | CKEditor 5 is a modern JavaScript rich-text editor with an MVC archite ... | check |
| CVE-2026-28687 | ImageMagick is free and open-source software used for editing and mani ... | For imagemagick6 superseded by fix inside jumbo patch for CVE-2026-28686, first patch was incomplete |
| CVE-2026-28687 | ImageMagick is free and open-source software used for editing and mani ... | Fixed by: https://github.com/ImageMagick/ImageMagick6/commit/6a602fb36f181a0089848344a3b0d79fc6155a2b (6.9.13-41) |
| CVE-2026-28688 | ImageMagick is free and open-source software used for editing and mani ... | For imagemagick6 by fix inside jumbo patch for CVE-2026-28686, first patch was incomplete |
| CVE-2026-28688 | ImageMagick is free and open-source software used for editing and mani ... | Fixed by: https://github.com/ImageMagick/ImageMagick6/commit/6a602fb36f181a0089848344a3b0d79fc6155a2b (6.9.13-41) |
| CVE-2026-29022 | dr_libs dr_wav.h version 0.14.4 and earlier (fixed in commit 8a7258c) ... | qtads, dosbox-x, roc-toolkit, octave-ltfat, faudio bundle a copy, check security impact |
| CVE-2026-30478 | A Dynamic-link Library Injection vulnerability in GatewayGeo MapServer ... | check |
| CVE-2026-30479 | A Dynamic-link Library Injection vulnerability in OSGeo Project MapSer ... | check |
| CVE-2026-30631 | An issue was discovered in bytebot-ai in commit 3d37894ce07ef8d8b40adc ... | check |
| CVE-2026-30632 | Directory traversal vulnerability in knowns-dev/knowns 0.11.4 via craf ... | check |
| CVE-2026-30633 | Directory traversal vulnerability in knowns-dev/knowns 0.11.4 via craf ... | check |
| CVE-2026-31053 | A double free vulnerability exists in librz/bin/format/le/le.c in the ... | check |
| CVE-2026-32148 | Insufficient Verification of Data Authenticity vulnerability in hexpm ... | check |
| CVE-2026-32313 | xmlseclibs is a library written in PHP for working with XML Encryption ... | check |
| CVE-2026-32600 | xml-security is a library that implements XML signatures and encryptio ... | check |
| CVE-2026-32635 | Angular is a development platform for building mobile and desktop web ... | check status for older versions |
| CVE-2026-33397 | The Angular SSR is a server-rise rendering tool for Angular applicatio ... | check |
| CVE-2026-34240 | JOSE is a Javascript Object Signing and Encryption (JOSE) library. Pri ... | check |
| CVE-2026-34316 | Vulnerability in the Oracle Commerce Service Center product of Oracle ... | check |
| CVE-2026-35287 | Vulnerability in Oracle Application Testing Suite. The supported ver ... | check |
| CVE-2026-35290 | Vulnerability in Oracle Application Testing Suite. The supported ver ... | check |
| CVE-2026-36189 | Buffer Overflow vulnerability in Uncrustify Project Affected v.Uncrust ... | check |
| CVE-2026-36499 | A missing upper-bound check in the udpif_set_threads() function of Ope ... | check, unclear status/validity |
| CVE-2026-39178 | A SQL injection vulnerability in SOGo before 5.12.7 allows authenticat ... | CVE-2026-39178 and CVE-2026-39179 are duplicates of CVE-2026-46445 and CVE-2026-46446, CNA contacted |
| CVE-2026-39179 | A SQL injection vulnerability in SOGo before 5.12.7 allows authenticat ... | CVE-2026-39178 and CVE-2026-39179 are duplicates of CVE-2026-46445 and CVE-2026-46446, CNA contacted |
| CVE-2026-39860 | Nix is a package manager for Linux and other Unix systems. A bug in th ... | check, potentially affecting guix if same issue in backporting fix for CVE-2024-2729 |
| CVE-2026-40033 | FreeRDP before 3.26.0 contains a heap-buffer-overflow vulnerability in ... | unclear fixing commit references, incorrect reference in CVE entry? |
| CVE-2026-40968 | When an authenticated user is denied access to a gRPC method, their au ... | check |
| CVE-2026-40969 | The raw message of every server-side AuthenticationException is return ... | check |
| CVE-2026-41889 | pgx is a PostgreSQL driver and toolkit for Go. Prior to version 5.9.2, ... | check the other golang-github-jackc-pgx* sources |
| CVE-2026-42199 | Grid is a data structure grid for rust. From version 0.17.0 to before ... | check |
| CVE-2026-42308 | Pillow is a Python imaging library. Prior to version 12.2.0, if a font ... | research fixing commit(s), maybe https://github.com/python-pillow/Pillow/pull/9518/changes |
| CVE-2026-42397 | Allocation of Resources Without Limits or Throttling (CWE-770) in Kiba ... | check |
| CVE-2026-42503 | gopls by default communicates via pipe. However, -port and -listen fla ... | check impact on golang-golang-x-tools |
| CVE-2026-43945 | FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) softwa ... | check |
| CVE-2026-43946 | FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) softwa ... | check |
| CVE-2026-43947 | FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) softwa ... | check |
| CVE-2026-44187 | A flaw was found in the Ansible Lightspeed extension for Visual Studio ... | check |
| CVE-2026-44189 | A flaw was found in the Visual Studio Code Ansible Lightspeed extensio ... | check |
| CVE-2026-44190 | A flaw was found in the Ansible Lightspeed Visual Studio Code extensio ... | check |
| CVE-2026-44191 | A flaw was found in the Visual Studio Code Ansible Lightspeed extensio ... | check |
| CVE-2026-44192 | A flaw was found in the Ansible Lightspeed Model Context Protocol (MCP ... | check |
| CVE-2026-44437 | The Angular SSR is a server-rise rendering tool for Angular applicatio ... | check |
| CVE-2026-44933 | `PluginScript` attempts to `chroot` the plugin to the `repoManagerRoot ... | check |
| CVE-2026-45388 | In OCaml-TLS before 2.1.0, the client implementation does insufficient ... | check |
| CVE-2026-45389 | In OCaml-TLS before 2.1.0, the server implementation does insufficient ... | check |
| CVE-2026-45390 | In OCaml-tar before 3.4.0, a crafted archive with ../ path segments in ... | check |
| CVE-2026-45820 | fflate through 0.8.2 is vulnerable to denial of service via an infinit ... | check |
| CVE-2026-46403 | Klever-Go is the Go implementation of the Klever blockchain protocol. ... | check |
| CVE-2026-46556 | FlaskBB is a Forum Software written in Python using the micro framewor ... | check |
| CVE-2026-46600 | Parsing an invalid SVCB or HTTPS RR can panic when the size of a param ... | check |
| CVE-2026-46727 | An issue was discovered in Ruby 4 before 4.0.5. A race condition leadi ... | check |
| CVE-2026-46876 | Vulnerability in Oracle Application Testing Suite. The supported ver ... | check |
| CVE-2026-46924 | Vulnerability in Oracle Application Testing Suite. The supported ver ... | check |
| CVE-2026-46936 | Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MyS ... | check |
| CVE-2026-46943 | Vulnerability in the Oracle Retail EFTLink product of Oracle Retail Ap ... | check |
| CVE-2026-46948 | Vulnerability in the Oracle Utilities Network Management System produc ... | check |
| CVE-2026-46980 | Vulnerability in the Oracle Utilities Network Management System produc ... | check |
| CVE-2026-46981 | Vulnerability in the Oracle Utilities Network Management System produc ... | check |
| CVE-2026-46982 | Vulnerability in the Oracle Retail Integration Bus product of Oracle R ... | check |
| CVE-2026-46983 | Vulnerability in the Oracle Retail Integration Bus product of Oracle R ... | check |
| CVE-2026-47007 | Vulnerability in the Oracle Communications Pricing Design Center produ ... | check |
| CVE-2026-47008 | Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MyS ... | check |
| CVE-2026-47012 | Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MyS ... | check |
| CVE-2026-47013 | Vulnerability in Oracle Java SE (component: JavaFX). The supported v ... | check |
| CVE-2026-47014 | Vulnerability in the Oracle Product Workbench product of Oracle E-Busi ... | check |
| CVE-2026-47022 | Vulnerability in the GoldenGate Stream Analytics product of Oracle Gol ... | check |
| CVE-2026-47023 | Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MyS ... | check |
| CVE-2026-47028 | Vulnerability in the Oracle Document Management and Collaboration prod ... | check |
| CVE-2026-47030 | Vulnerability in Oracle Java SE (component: JavaFX). The supported v ... | check |
| CVE-2026-47031 | Vulnerability in the Oracle Bills of Material product of Oracle E-Busi ... | check |
| CVE-2026-47033 | Vulnerability in the Oracle Contracts Integration product of Oracle E- ... | check |
| CVE-2026-47034 | Vulnerability in Oracle Java SE (component: JavaFX). The supported v ... | check |
| CVE-2026-47035 | Vulnerability in Oracle Java SE (component: JavaFX). The supported v ... | check |
| CVE-2026-47036 | Vulnerability in the Siebel CRM Development product of Oracle Siebel C ... | check |
| CVE-2026-47040 | Vulnerability in the Oracle Net Services component of Oracle Database ... | check |
| CVE-2026-47041 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualiza ... | check |
| CVE-2026-47043 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualiza ... | check |
| CVE-2026-47044 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualiza ... | check |
| CVE-2026-47047 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualiza ... | check |
| CVE-2026-47050 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualiza ... | check |
| CVE-2026-47052 | Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MyS ... | check |
| CVE-2026-47053 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualiza ... | check |
| CVE-2026-47054 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualiza ... | check |
| CVE-2026-47055 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualiza ... | check |
| CVE-2026-47062 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualiza ... | check |
| CVE-2026-47064 | Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MyS ... | check |
| CVE-2026-47143 | Capstone is a disassembly framework. Versions prior to 6.0.0-Alpha8 an ... | check |
| CVE-2026-47237 | Kubeflow Community Distribution helps users to install Kubeflow Platfo ... | check |
| CVE-2026-47667 | CImg Library is a C++ library for image processing. Prior to version 4 ... | check |
| CVE-2026-47671 | Nhost is an open source Firebase alternative with GraphQL. In versions ... | check |
| CVE-2026-47685 | FOG is a free open-source cloning/imaging/rescue suite/inventory manag ... | check |
| CVE-2026-47687 | FOG is a free open-source cloning/imaging/rescue suite/inventory manag ... | check |
| CVE-2026-47688 | FOG is a free open-source cloning/imaging/rescue suite/inventory manag ... | check |
| CVE-2026-47689 | FOG is a free open-source cloning/imaging/rescue suite/inventory manag ... | check |
| CVE-2026-47690 | MeltanoHub is the source code for hub.meltano.com, the central place f ... | check |
| CVE-2026-47695 | CC: Tweaked is a mod for Minecraft which adds programmable computers, ... | check |
| CVE-2026-47697 | Shelf is a platform for tracking physical assets. Shelf is multi-tenan ... | check |
| CVE-2026-47708 | MCP-for-Stata is an MCP server for Stata to integrate Stata into an ag ... | check |
| CVE-2026-47731 | The AMMOS Instrument Toolkit (Formerly the Bespoke Links to Instrument ... | check |
| CVE-2026-49092 | Unintended Proxy or Intermediary ('Confused Deputy') (CWE-441) in Kiba ... | check |
| CVE-2026-49294 | Valhalla is an open source routing engine and accompanying libraries f ... | check |
| CVE-2026-53910 | diff3tool from GNU diffutilsis vulnerable to a heap\u2011based buffer ... | check |
| CVE-2026-55223 | c3p0 is a JDBC Connection pooling library. In versions prior to 0.14.0 ... | check if that is an issue with the packaged version |
| CVE-2026-55654 | A flaw was found in OpenSSH. This vulnerability, a heap out-of-bounds ... | check details, AI generated report |
| CVE-2026-55655 | A flaw was found in OpenSSH. A local unprivileged attacker on a Linux ... | check details, AI generated report |
| CVE-2026-55851 | Netty is a network application framework for development of protocol s ... | check |
| CVE-2026-56146 | Improper Access Control (CWE-284) in Kibana can lead to unauthorized m ... | check |
| CVE-2026-56147 | Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana c ... | check |
| CVE-2026-56745 | Netty is a network application framework for development of protocol s ... | check |
| CVE-2026-56746 | Netty is a network application framework for development of protocol s ... | check |
| CVE-2026-56816 | Netty is a network application framework for development of protocol s ... | check |
| CVE-2026-56817 | Netty is a network application framework for development of protocol s ... | check |
| CVE-2026-56819 | Netty is a network application framework for development of protocol s ... | check |
| CVE-2026-56820 | Netty is a network application framework for development of protocol s ... | check |
| CVE-2026-56852 | A norm.Iter can enter an infinite loop when handling input containing ... | check |
| CVE-2026-58050 | libssh2 through 1.11.1 reads an attacker-controlled 32-bit attribute c ... | check with upstream, only affecting libssh2 on Winddows? |
| CVE-2026-58051 | libssh2 through 1.11.1 grows its publickey list with SSH2_REALLOC but ... | check with upstream, only affecting libssh2 on Winddows? |
| CVE-2026-59674 | A UNIX Symbolic Link (Symlink) Following vulnerability in openSUSE Tum ... | check |
| CVE-2026-59843 | A flaw was found in libssh. A remote authenticated peer can advertise ... | check fixing commit in libssh-0.12.1 |