Bugs with TODO items

Hide "check" TODOs

BugDescriptionNote
CVE-2016-1584In all versions of Unity8 a running but not active application on a la ...check proper tracking update
CVE-2016-20096Linknat VOS3000 and VOS2009 through version 2.1.2.0 contain an unauthe ...check
CVE-2018-25246Wikipedia 12.0 contains a denial of service vulnerability that allows ...check
CVE-2018-25305librsvg2-bin 2.40.13 contains a buffer overflow vulnerability that all ...check
CVE-2018-25306PDFunite 0.41.0 contains a buffer overflow vulnerability that allows l ...check
CVE-2019-25485R 3.4.4 on Windows x64 contains a buffer overflow vulnerability in the ...check
CVE-2019-25683FileZilla 3.40.0 contains a denial of service vulnerability in the loc ...check
CVE-2021-27137An issue was discovered in router/upnp/src/ssdp.c in DD-WRT before 457 ...check
CVE-2022-23538github.com/sylabs/scs-library-client is the Go client for the Singular ...check details, might as well affect golang-github-apptainer-container-library-client
CVE-2022-50942Incinga Web 2.8.2 contains a client-side cross-site scripting vulnerab ...check status upstream
CVE-2023-26044react/http is an event-driven, streaming HTTP client and server implem ...check, is embedded inicinga-php-thirdparty, icingaweb2-module-reactbundle possibly affected
CVE-2023-47268In libslic3r/GCode/PostProcessor.cpp in Prusa PrusaSlicer through 2.6. ...check
CVE-2023-49316In Math/BinaryField.php in phpseclib 3 before 3.0.34, excessively larg ...check if affecting ldap-account-manager or unused path
CVE-2023-49899An unauthenticated remote attacker canexecute any command on the affec ...check
CVE-2023-49900An unauthenticated remote attacker is able to perform remote code exec ...check
CVE-2023-50251php-svg-lib is an SVG file parsing / rendering library. Prior to versi ...check, other packages are embedding the library: civicrm, icinga-php-thirdparty and icingaweb2 to be checked
CVE-2023-50252php-svg-lib is an SVG file parsing / rendering library. Prior to versi ...check, other packages are embedding the library: civicrm, icinga-php-thirdparty and icingaweb2 to be checked
CVE-2023-50262Dompdf is an HTML to PDF converter for PHP. When parsing SVG images Do ...check sources embedding php-dompdf if affected
CVE-2024-7708For requests that have a body, but reading the body may end up in read ...check
CVE-2024-22420JupyterLab is an extensible environment for interactive and reproducib ...check completeness, src:jupyter-notebook?
CVE-2024-22421JupyterLab is an extensible environment for interactive and reproducib ...check completeness, src:jupyter-notebook?
CVE-2024-32385An issue in Kerlink Kerlink Wirnet iStation 868 KerOS v.4.3.3_20200803 ...check
CVE-2024-32386Directory traversal vulnerability in Kerlink Kerlink Wirnet iStation 8 ...check
CVE-2024-32387An issue in Kerlink Kerlink Wirnet iStation 868 KerOS v.4.3.3_20200803 ...check
CVE-2024-32389Buffer Overflow vulnerability in Kerlink Kerlink Wirnet iStation 868 K ...check
CVE-2024-34268EQ-3 Eqiva CC-RT-BLE Bluetooth Smart Radiator Thermostat Firmware up t ...check
CVE-2024-47091Privilege escalation in the mk_mysql agent plugin on Windows in Checkm ...check
CVE-2024-54192An issue inTcpreplay v4.5.1 allows a local attacker to cause a denial ...check
CVE-2024-58360stoatchat versions before 0.7.8 fail to enforce account creation restr ...check
CVE-2025-3110OpenVPN Access Server 2.7.2 through 3.1.0 accepts bare line-feed seque ...check
CVE-2025-4382A flaw was found in systems utilizing LUKS-encrypted disks with GRUB c ...double check if vulnerability only considered present after grub_is_cli_disabled is introduced
CVE-2025-6499A vulnerability classified as problematic was found in vstakhov libucl ...check if impacts security wise rspamd, which embeds libucl and uses it a compile time
CVE-2025-8412A Buffer Copy without Checking Size of Input ('Classic Buffer Overflow ...check
CVE-2025-8671A mismatch caused by client-triggered server-sent stream resets betwee ...check, some projects will assign own CVEs and should then be covered under that specific CVE instead
CVE-2025-8941A flaw was found in linux-pam. The pam_namespace module may improperly ...check likely RedHat specific incomplete fix for CVE-2025-6020, but asked to pinpoint incomplete fixes
CVE-2025-11010A vulnerability has been found in vstakhov libucl up to 0.9.2. Affecte ...check if impacts security wise rspamd, which embeds libucl and uses it a compile time
CVE-2025-11147Reflected cross-site scripting (XSS) in Apt-Cacher-NG v3.2.1. The vuln ...clarifying with reporter and Eduard Bloch on the issue.
CVE-2025-14575An Uncontrolled Search Path Element vulnerability in the OpenSSL TLS b ...check
CVE-2025-15569A flaw has been found in Artifex MuPDF up to 1.26.1 on Windows. The im ...check
CVE-2025-15667A vulnerability was determined in GPAC up to 2.5-DEV. This vulnerabili ...check
CVE-2025-15668A vulnerability was identified in GPAC up to b40ce70f5. This issue aff ...check
CVE-2025-30007HestiaCP before 1.9.5 contains an authenticated OS command injection v ...check
CVE-2025-30008HestiaCP before 1.9.5 contains a stored cross-site scripting vulnerabi ...check
CVE-2025-32781Apollo is a reliable configuration management system suitable for micr ...check
CVE-2025-33221NVIDIA Display Driver for Windows and Linux contains a vulnerability i ...check
CVE-2025-45422Incorrect access control in Proximus b-box v8c.725A allows authenticat ...check
CVE-2025-45868LogicalDOC Enterprise up to and for v9.1.1 is vulnerable to blind SQL ...check
CVE-2025-45870LogicalDOC Enterprise up to and for v9.1.1 is vulnerable to Local File ...check
CVE-2025-51677An issue was discovered in openRISC OR1200 commit 83ac6b. An output mi ...check
CVE-2025-51678An issue was discovered in RISC-V PicoRV32 commit 87c89a. A mismatch i ...check
CVE-2025-56361A reachable assertion vulnerability exists in the Matter SDK (connecte ...check
CVE-2025-56362A reachable assertion vulnerability exists in the Matter SDK (connecte ...check
CVE-2025-56363A null pointer dereference vulnerability exists in the Matter SDK (con ...check
CVE-2025-56364A use of uninitialized value vulnerability exists in the Matter SDK (c ...check
CVE-2025-56365A reachable assertion vulnerability exists in the Matter SDK (connecte ...check
CVE-2025-58064CKEditor 5 is a modern JavaScript rich-text editor with an MVC archite ...check
CVE-2025-60357AhnLab EPP Management v1.0.14.32-6249 was discovered to contain a NoSQ ...check
CVE-2025-60796phpPgAdmin 7.13.0 and earlier contains multiple cross-site scripting ( ...check, possibly not reported upstream
CVE-2025-60797phpPgAdmin 7.13.0 and earlier contains a SQL injection vulnerability i ...check, possibly not reported upstream
CVE-2025-60798phpPgAdmin 7.13.0 and earlier contains a SQL injection vulnerability i ...check, possibly not reported upstream
CVE-2025-60799phpPgAdmin 7.13.0 and earlier contains an incorrect access control vul ...check, possibly not reported upstream
CVE-2025-61261A reflected cross-site scripting (XSS) vulnerability in CKeditor v46.1 ...check
CVE-2025-61982An arbitrary code execution vulnerability exists in the Code Stream di ...check upstream status
CVE-2025-65720An issue in Open Source GPT Researcher v3.3.7 allows attackers to exec ...check
CVE-2025-66390In Microsoft Azure API Management through 2025-10-17, when self-servic ...check
CVE-2025-66578xmlseclibs is a library written in PHP for working with XML Encryption ...check
CVE-2025-67108eProsima Fast-DDS v3.3 was discovered to contain improper validation f ...check https://gist.github.com/lkloliver/81b5d5a8328d712dbfd497bf11dbe913, unclear if reported upstream
CVE-2025-68640The Apple Find My backend service through 2025-12-17 allows an attacke ...check
CVE-2025-69534Python-Markdown version 3.8 contain a vulnerability where malformed HT ...Asking whether it really needs a backport: https://bugs.debian.org/1131896
CVE-2025-69720The infocmp command-line tool in ncurses before 6.5-20251213 has a sta ...check upstream status
CVE-2025-69969A lack of authentication and authorization mechanisms in the Bluetooth ...check
CVE-2025-70796An unauthenticated path traversal vulnerability exists in the web mana ...check
CVE-2025-70887An issue in ralphje Signify before v.0.9.2 allows a remote attacker to ...check
CVE-2025-71377stoatchat (delta) versions before 20250210-1 (0.8.2) contain a logic e ...check
CVE-2025-71388stoatchat (delta/Revolt) versions from 20241213-1 before 20250210-1 al ...check
CVE-2026-0708A flaw was found in libucl. A remote attacker could exploit this by pr ...check if impacts security wise rspamd, which embeds libucl and uses it a compile time
CVE-2026-1703When pip is installing and extracting a maliciously crafted wheel arch ...check as well pipenv
CVE-2026-2395Improper neutralization of special elements used in an SQL command ('S ...check
CVE-2026-2406Authorization bypass through User-Controlled key vulnerability in Univ ...check
CVE-2026-4773Improper validation of specified type of input vulnerability in Magars ...check
CVE-2026-4833A weakness has been identified in Orc discount up to 3.0.1.2. This iss ...check libtext-markdown-discount-perl, ruby-rdiscount, cantor, embedding discount; check if security impact present
CVE-2026-7701A security vulnerability has been detected in Telegram Desktop up to 6 ...check upstream reports
CVE-2026-7790Uncontrolled Resource Consumption vulnerability in ninenines cowlib (c ...check if embedded copy in rabbitmq-server is problematic
CVE-2026-8484A heap buffer overflow vulnerability exists in the Jansi JNI "ioctl()" ...double-check source packages, as there is not much details from cert.pl post
CVE-2026-8851SOGo versions 5.12.7 and prior contains a SQL injection vulnerability ...check correctness
CVE-2026-8863Multiple Microsoft-sigend UEFI SHIM bootloaders are vulnerable to Secu ...check
CVE-2026-10037A sandbox escape vulnerability exists in the OpenJDK packages provided ...check
CVE-2026-10051In Eclipse Jetty, a first HTTP/1.1 request with trailers causes the se ...check
CVE-2026-10097wolfSSL's AVX2-optimized ML-KEM implementation (mlkem_cmp_avx2) compar ...check
CVE-2026-10098OCSP CertID serial-number length-confusion in wolfSSL_OCSP_resp_find_s ...check
CVE-2026-10130QueryWeaver contains an authentication bypass vulnerability that allow ...check
CVE-2026-10512The X25519 x86_64 assembly implementation fails to clear the most sign ...check
CVE-2026-10592Certificates with wildcard DNS SANs (e.g. *.example.com) bypassed CA n ...check
CVE-2026-10706In Adalo\u2019s no-code app builder, (Versions 1 and 2) the attackers ...check
CVE-2026-10708This vulnerability enables large\u2011scale data harvesting without re ...check
CVE-2026-11310X.509 trust-chain bypass in the OpenSSL compatibility certificate veri ...check
CVE-2026-11321The DataInjection plugin for GLPI 2.15.6 (GLPI 11 builds) concatenates ...check
CVE-2026-11386An input validation and injection vulnerability exists in Canonical ub ...check
CVE-2026-11404Cesanta Mongoose before 7.22 contains an out-of-bounds read in the bui ...check
CVE-2026-11703Missing SNI/ALPN binding on stateful (session-ID) resumption, which pr ...check
CVE-2026-11763Authorization bypass through User-Controlled key vulnerability in Gis ...check
CVE-2026-11876In zenml-io/zenml version 0.94.2, the `GET /api/v1/stack-deployment/st ...check
CVE-2026-11889SALTO ProAccess Space software using the tenancy feature / logical pa ...check
CVE-2026-11944openSIS Classic 9.3 contains an authenticated path traversal vulnerabi ...check
CVE-2026-11999X.509 trust-chain bypass (path-depth exhaustion) in the OpenSSL compat ...check
CVE-2026-12080A flaw was found in the QEMU Guest Agent (qga). A local unprivileged u ...check
CVE-2026-12228A stored cross-site scripting (XSS) vulnerability exists in the `POST ...check
CVE-2026-12340Out-of-bounds heap read during SM2/SM3 certificate signature verificat ...check
CVE-2026-12341This vulnerability impacts all versions of IdentityIQ and allows an un ...check
CVE-2026-12379An Open Redirect vulnerability (CWE-601) exists in the OAuth/OIDC auth ...check
CVE-2026-12382A flaw was found in the AAP Gateway Envoy proxy configuration. The non ...check
CVE-2026-12391An insecure symlink following vulnerability exists in Canonical ubuntu ...check
CVE-2026-12478The fix for CVE-2026-0716 (commit 6ff7ef0, libsoup 3.6.6) placed the i ...check
CVE-2026-12482A vulnerability in keras-team/keras version 3.12.0 allows an attacker ...check
CVE-2026-12484A vulnerability in keras-team/keras version 3.15.0 allows unsafe deser ...check
CVE-2026-12523Summary Cloudflare quiche's HTTP/3 layer was discovered to be vulne ...check
CVE-2026-12547SoupAuthManager caches proxy authentication credentials without scopin ...check
CVE-2026-12548A heap out-of-bounds read flaw was found in libsoup. When parsing mult ...check
CVE-2026-12590Impact: In body-parser versions prior to 1.20.6 (1.x line) and 2.3.0 ( ...check
CVE-2026-12593The implementation of an internalandundocumentedDashboardAPI endpoint( ...check
CVE-2026-12606Eclipse Grizzly in versions before 5.0.2, cannot properly parse the tr ...check
CVE-2026-12616The /v1/upload/sbom endpoint extracts the iss claim from the attacker- ...check
CVE-2026-12681Improper Validation of Specified Index, Position, or Offset in Input v ...check
CVE-2026-12691Missing authentication for critical function vulnerability in Vimesoft ...check
CVE-2026-12692Unverified password change vulnerability in Vimesoft Inc. Enterprise V ...check
CVE-2026-12693Authorization bypass through User-Controlled key vulnerability in Vime ...check
CVE-2026-12694Missing Authorization vulnerability in Vimesoft Inc. Enterprise Video ...check
CVE-2026-12701A path traversal vulnerability was found in pulpcore. The relative_pat ...check
CVE-2026-12707Summary Cloudflare quiche was discovered to be vulnerable to memory ...check
CVE-2026-12715Missing Authorization in Google Cloud Firebase Studio versions prior t ...check
CVE-2026-13380VSee Clinic 7.1.26 and VSee Clinic API 1.3.0 exposes cleartext SFTP cr ...check
CVE-2026-13381VSee Clinic 7.1.26 and API1.3.0contain an Insecure Direct Object Refer ...check
CVE-2026-13500A weakness has been identified in antlr ANTLR4 up to 4.13.2. Affected ...check upstream reporting and status
CVE-2026-13501A security vulnerability has been detected in antlr ANTLR4 up to 4.13. ...check upstream reporting and status
CVE-2026-13502A flaw has been found in antlr ANTLR4 up to 4.13.2. This affects the f ...check upstream reporting and status
CVE-2026-13503A vulnerability was detected in antlr ANTLR4 up to 4.13.2. Affected by ...check upstream reporting and status
CVE-2026-13724Client-Side Enforcement of Server-Side Security vulnerability in Gobit ...check
CVE-2026-14191An out-of-bounds heap write exists in the RAR5 recovery-volume (.rev) ...check
CVE-2026-14448An high privileged remote attacker can exploit an authenticated OS com ...check
CVE-2026-14551The servereye client (also known as sensorhub, technically ClientAgent ...check
CVE-2026-14906Pages with malicious titles could potentially allow saved PDF content ...check
CVE-2026-14985The Analog Way Picturall Quad Compact Mark II version 3.5.8, contains ...check
CVE-2026-15034A vulnerability has been found in flask-dashboard Flask-MonitoringDash ...check
CVE-2026-15063A flaw was found in the gorch service template, which is part of the t ...check
CVE-2026-15308The incremental HTML parser (html.parser.HTMLParser) allows for CPU de ...check
CVE-2026-15588A denial-of-service and resource exhaustion vulnerability exists withi ...check
CVE-2026-15690A vulnerability was identified in open62541 up to 1.5.5. Affected by t ...check
CVE-2026-15709A flaw was found in libsoup's WebSocket implementation when using the ...check
CVE-2026-15711A vulnerability was found in libsoup's WebSocket frame parsing impleme ...check
CVE-2026-15712A heap buffer over-read vulnerability was discovered in libsoup's (ver ...check
CVE-2026-15713A vulnerability was found in libsoup's HTTP/2 protocol implementation. ...check
CVE-2026-15714An out-of-bounds read vulnerability was found in libsoup's multipart p ...check
CVE-2026-15779A flaw was found in samba's pam_winbind. When mkhomedir is enabled, pa ...check if Red Hat specific
CVE-2026-15788BuildKit's cache mount source= selector on Windows Container on Window ...check
CVE-2026-15789A custom client can produce such an upload request to the BuildKit dae ...check
CVE-2026-15791A crafted message in the BuildKit low-level build API can be used to r ...check
CVE-2026-15792A malicious BuildKit client or frontend could craft a request that cou ...check
CVE-2026-15793BuildKit custom frontends or clients using the raw low-level API can s ...check
CVE-2026-15811A vulnerability was found in kronosnet's (version <=1.34) cryptographi ...check
CVE-2026-15812A vulnerability was found in the internal Access Control List (ACL) su ...check
CVE-2026-15813A vulnerability was found in the network packet de-fragmentation engin ...check
CVE-2026-15829A SQL injection (CWE-89) and security boundary bypass (CWE-863) vulner ...check
CVE-2026-16118A flaw was found in xdgmime. A heap-based buffer overflow can be trigg ...check
CVE-2026-16157Duplicati v2.3.0.1 backup software gives Authenticated Users MODIFY pe ...check
CVE-2026-16232An authentication bypass vulnerability in the Check Point SmartConsole ...check
CVE-2026-16254A flaw was found in claircore's apk package scanner. Malformed package ...check
CVE-2026-16270Open Mercato does not validate regex rules. An attacker with privilege ...check
CVE-2026-16454InEclipse hawkBitversions 1.0.3 and prior, a privilege escalation vuln ...check
CVE-2026-16473A flaw was found in the sbc library (BlueZ SBC codec). An off-by-one e ...check
CVE-2026-16488A vulnerability was determined in QUSETIONS MiniCode-Python 0.1.0. Thi ...check
CVE-2026-16489A vulnerability was identified in jsforce up to 3.10.16. This issue af ...check
CVE-2026-16492A weakness has been identified in umijs umi up to 4.6.63. The affected ...check
CVE-2026-16493A flaw was found in ansible-core. The _extract_collection_from_git() f ...check upstream details
CVE-2026-16517A signed integer overflow vulnerability was found in libarchive's ZIP ...check
CVE-2026-16544A flaw was found in AWX. The websocket event consumer performs RBAC au ...check
CVE-2026-16551Denial-of-Service in Thinkst Applied Research OpenCanary (MongoDB modu ...check
CVE-2026-16552A flaw was found in systemd-tmpfiles. When processing a tmpfiles.d con ...check
CVE-2026-16560A heap-buffer-overflow flaw was found in Directory Server (389-ds-base ...check
CVE-2026-16606A vulnerability in Fujitsu Software Linux openFT andFujitsu Software O ...check
CVE-2026-16607A vulnerability in Fujitsu Software Linux openFT andFujitsu Software O ...check
CVE-2026-16615A flaw was found in librest. The PKCE implementation for OAuth authori ...check
CVE-2026-16624Cal.com OSS ships lacks authorization on webhook teamId creation, allo ...check
CVE-2026-21953Vulnerability in the Oracle Retail Xstore Point of Service product of ...check
CVE-2026-21954Vulnerability in the Oracle Retail Xstore Point of Service product of ...check
CVE-2026-22739Vulnerability in Spring Cloud when substituting the profile parameter ...check
CVE-2026-22752Authentication bypass by primary weakness vulnerability in Spring Secu ...check
CVE-2026-23479Redis is an in-memory data structure store. In redis-server from 7.2.0 ...check redict and valkey
CVE-2026-23631Redis is an in-memory data structure store. In all versions of redis-s ...check redict and valkey
CVE-2026-24182NVIDIA Display Driver for Windows and Linux contains a vulnerability w ...check
CVE-2026-24187NVIDIA Display Driver for Linux contains a vulnerability where an atta ...check
CVE-2026-24190NVIDIA Display Driver for Windows and Linux contains a vulnerability i ...check
CVE-2026-24191NVIDIA Display Driver for Windows contains a vulnerability where an at ...check
CVE-2026-24192NVIDIA Display Driver for Linux contains a vulnerability where an atta ...check
CVE-2026-24193NVIDIA Display Driver for Windows and Linux contains a vulnerability w ...check
CVE-2026-24194NVIDIA Display Driver for Linux contains a vulnerability in a kernel m ...check
CVE-2026-24195NVIDIA Display Driver for Linux contains a vulnerability in UVM, where ...check
CVE-2026-24196NVIDIA Display Driver for Linux contains a vulnerability where a user ...check
CVE-2026-24197NVIDIA Display Driver for Linux contains a vulnerability in the Multi- ...check
CVE-2026-24198NVIDIA GPU Display Driver for Linux contains a vulnerability where an ...check
CVE-2026-24199NVIDIA Display Driver for Linux contains a vulnerability in a kernel m ...check
CVE-2026-24232NVIDIA Tranformers4Rec contains a vulnerability where an attacker coul ...check
CVE-2026-25243Redis is an in-memory data structure store. In versions of redis-serve ...check redict and valkey
CVE-2026-25701An Insecure Temporary File vulnerability in openSUSE sdbootutil allows ...check
CVE-2026-25702A Improper Access Control vulnerability in the kernel of SUSE SUSE Lin ...check
CVE-2026-26197HDF5 is a high-performance library and a file format specification tha ...check, isolate upstream change, might only be relevant for 2.0.0 onwards
CVE-2026-26199HDF5 is a high-performance library and a file format specification tha ...isolate fixing commit
CVE-2026-27586Caddy is an extensible server platform that uses TLS by default. Prior ...check, introducing version
CVE-2026-27704The Dart and Flutter SDKs provide software development kits for the Da ...check
CVE-2026-27738The Angular SSR is a server-rise rendering tool for Angular applicatio ...check
CVE-2026-27739The Angular SSR is a server-rise rendering tool for Angular applicatio ...check
CVE-2026-27970Angular is a development platform for building mobile and desktop web ...check status for older versions
CVE-2026-28343CKEditor 5 is a modern JavaScript rich-text editor with an MVC archite ...check
CVE-2026-28687ImageMagick is free and open-source software used for editing and mani ...For imagemagick6 superseded by fix inside jumbo patch for CVE-2026-28686, first patch was incomplete
CVE-2026-28687ImageMagick is free and open-source software used for editing and mani ...Fixed by: https://github.com/ImageMagick/ImageMagick6/commit/6a602fb36f181a0089848344a3b0d79fc6155a2b (6.9.13-41)
CVE-2026-28688ImageMagick is free and open-source software used for editing and mani ...For imagemagick6 by fix inside jumbo patch for CVE-2026-28686, first patch was incomplete
CVE-2026-28688ImageMagick is free and open-source software used for editing and mani ...Fixed by: https://github.com/ImageMagick/ImageMagick6/commit/6a602fb36f181a0089848344a3b0d79fc6155a2b (6.9.13-41)
CVE-2026-29022dr_libs dr_wav.h version 0.14.4 and earlier (fixed in commit 8a7258c) ...qtads, dosbox-x, roc-toolkit, octave-ltfat, faudio bundle a copy, check security impact
CVE-2026-30478A Dynamic-link Library Injection vulnerability in GatewayGeo MapServer ...check
CVE-2026-30479A Dynamic-link Library Injection vulnerability in OSGeo Project MapSer ...check
CVE-2026-30631An issue was discovered in bytebot-ai in commit 3d37894ce07ef8d8b40adc ...check
CVE-2026-30632Directory traversal vulnerability in knowns-dev/knowns 0.11.4 via craf ...check
CVE-2026-30633Directory traversal vulnerability in knowns-dev/knowns 0.11.4 via craf ...check
CVE-2026-31053A double free vulnerability exists in librz/bin/format/le/le.c in the ...check
CVE-2026-32148Insufficient Verification of Data Authenticity vulnerability in hexpm ...check
CVE-2026-32313xmlseclibs is a library written in PHP for working with XML Encryption ...check
CVE-2026-32600xml-security is a library that implements XML signatures and encryptio ...check
CVE-2026-32635Angular is a development platform for building mobile and desktop web ...check status for older versions
CVE-2026-33397The Angular SSR is a server-rise rendering tool for Angular applicatio ...check
CVE-2026-34240JOSE is a Javascript Object Signing and Encryption (JOSE) library. Pri ...check
CVE-2026-34316Vulnerability in the Oracle Commerce Service Center product of Oracle ...check
CVE-2026-35287Vulnerability in Oracle Application Testing Suite. The supported ver ...check
CVE-2026-35290Vulnerability in Oracle Application Testing Suite. The supported ver ...check
CVE-2026-36189Buffer Overflow vulnerability in Uncrustify Project Affected v.Uncrust ...check
CVE-2026-36499A missing upper-bound check in the udpif_set_threads() function of Ope ...check, unclear status/validity
CVE-2026-39178A SQL injection vulnerability in SOGo before 5.12.7 allows authenticat ...CVE-2026-39178 and CVE-2026-39179 are duplicates of CVE-2026-46445 and CVE-2026-46446, CNA contacted
CVE-2026-39179A SQL injection vulnerability in SOGo before 5.12.7 allows authenticat ...CVE-2026-39178 and CVE-2026-39179 are duplicates of CVE-2026-46445 and CVE-2026-46446, CNA contacted
CVE-2026-39860Nix is a package manager for Linux and other Unix systems. A bug in th ...check, potentially affecting guix if same issue in backporting fix for CVE-2024-2729
CVE-2026-40033FreeRDP before 3.26.0 contains a heap-buffer-overflow vulnerability in ...unclear fixing commit references, incorrect reference in CVE entry?
CVE-2026-40968When an authenticated user is denied access to a gRPC method, their au ...check
CVE-2026-40969The raw message of every server-side AuthenticationException is return ...check
CVE-2026-41889pgx is a PostgreSQL driver and toolkit for Go. Prior to version 5.9.2, ...check the other golang-github-jackc-pgx* sources
CVE-2026-42199Grid is a data structure grid for rust. From version 0.17.0 to before ...check
CVE-2026-42308Pillow is a Python imaging library. Prior to version 12.2.0, if a font ...research fixing commit(s), maybe https://github.com/python-pillow/Pillow/pull/9518/changes
CVE-2026-42397Allocation of Resources Without Limits or Throttling (CWE-770) in Kiba ...check
CVE-2026-42503gopls by default communicates via pipe. However, -port and -listen fla ...check impact on golang-golang-x-tools
CVE-2026-43945FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) softwa ...check
CVE-2026-43946FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) softwa ...check
CVE-2026-43947FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) softwa ...check
CVE-2026-44187A flaw was found in the Ansible Lightspeed extension for Visual Studio ...check
CVE-2026-44189A flaw was found in the Visual Studio Code Ansible Lightspeed extensio ...check
CVE-2026-44190A flaw was found in the Ansible Lightspeed Visual Studio Code extensio ...check
CVE-2026-44191A flaw was found in the Visual Studio Code Ansible Lightspeed extensio ...check
CVE-2026-44192A flaw was found in the Ansible Lightspeed Model Context Protocol (MCP ...check
CVE-2026-44437The Angular SSR is a server-rise rendering tool for Angular applicatio ...check
CVE-2026-44933`PluginScript` attempts to `chroot` the plugin to the `repoManagerRoot ...check
CVE-2026-45388In OCaml-TLS before 2.1.0, the client implementation does insufficient ...check
CVE-2026-45389In OCaml-TLS before 2.1.0, the server implementation does insufficient ...check
CVE-2026-45390In OCaml-tar before 3.4.0, a crafted archive with ../ path segments in ...check
CVE-2026-45820fflate through 0.8.2 is vulnerable to denial of service via an infinit ...check
CVE-2026-46403Klever-Go is the Go implementation of the Klever blockchain protocol. ...check
CVE-2026-46556FlaskBB is a Forum Software written in Python using the micro framewor ...check
CVE-2026-46600Parsing an invalid SVCB or HTTPS RR can panic when the size of a param ...check
CVE-2026-46727An issue was discovered in Ruby 4 before 4.0.5. A race condition leadi ...check
CVE-2026-46876Vulnerability in Oracle Application Testing Suite. The supported ver ...check
CVE-2026-46924Vulnerability in Oracle Application Testing Suite. The supported ver ...check
CVE-2026-46936Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MyS ...check
CVE-2026-46943Vulnerability in the Oracle Retail EFTLink product of Oracle Retail Ap ...check
CVE-2026-46948Vulnerability in the Oracle Utilities Network Management System produc ...check
CVE-2026-46980Vulnerability in the Oracle Utilities Network Management System produc ...check
CVE-2026-46981Vulnerability in the Oracle Utilities Network Management System produc ...check
CVE-2026-46982Vulnerability in the Oracle Retail Integration Bus product of Oracle R ...check
CVE-2026-46983Vulnerability in the Oracle Retail Integration Bus product of Oracle R ...check
CVE-2026-47007Vulnerability in the Oracle Communications Pricing Design Center produ ...check
CVE-2026-47008Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MyS ...check
CVE-2026-47012Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MyS ...check
CVE-2026-47013Vulnerability in Oracle Java SE (component: JavaFX). The supported v ...check
CVE-2026-47014Vulnerability in the Oracle Product Workbench product of Oracle E-Busi ...check
CVE-2026-47022Vulnerability in the GoldenGate Stream Analytics product of Oracle Gol ...check
CVE-2026-47023Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MyS ...check
CVE-2026-47028Vulnerability in the Oracle Document Management and Collaboration prod ...check
CVE-2026-47030Vulnerability in Oracle Java SE (component: JavaFX). The supported v ...check
CVE-2026-47031Vulnerability in the Oracle Bills of Material product of Oracle E-Busi ...check
CVE-2026-47033Vulnerability in the Oracle Contracts Integration product of Oracle E- ...check
CVE-2026-47034Vulnerability in Oracle Java SE (component: JavaFX). The supported v ...check
CVE-2026-47035Vulnerability in Oracle Java SE (component: JavaFX). The supported v ...check
CVE-2026-47036Vulnerability in the Siebel CRM Development product of Oracle Siebel C ...check
CVE-2026-47040Vulnerability in the Oracle Net Services component of Oracle Database ...check
CVE-2026-47041Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualiza ...check
CVE-2026-47043Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualiza ...check
CVE-2026-47044Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualiza ...check
CVE-2026-47047Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualiza ...check
CVE-2026-47050Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualiza ...check
CVE-2026-47052Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MyS ...check
CVE-2026-47053Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualiza ...check
CVE-2026-47054Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualiza ...check
CVE-2026-47055Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualiza ...check
CVE-2026-47062Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualiza ...check
CVE-2026-47064Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MyS ...check
CVE-2026-47143Capstone is a disassembly framework. Versions prior to 6.0.0-Alpha8 an ...check
CVE-2026-47237Kubeflow Community Distribution helps users to install Kubeflow Platfo ...check
CVE-2026-47667CImg Library is a C++ library for image processing. Prior to version 4 ...check
CVE-2026-47671Nhost is an open source Firebase alternative with GraphQL. In versions ...check
CVE-2026-47685FOG is a free open-source cloning/imaging/rescue suite/inventory manag ...check
CVE-2026-47687FOG is a free open-source cloning/imaging/rescue suite/inventory manag ...check
CVE-2026-47688FOG is a free open-source cloning/imaging/rescue suite/inventory manag ...check
CVE-2026-47689FOG is a free open-source cloning/imaging/rescue suite/inventory manag ...check
CVE-2026-47690MeltanoHub is the source code for hub.meltano.com, the central place f ...check
CVE-2026-47695CC: Tweaked is a mod for Minecraft which adds programmable computers, ...check
CVE-2026-47697Shelf is a platform for tracking physical assets. Shelf is multi-tenan ...check
CVE-2026-47708MCP-for-Stata is an MCP server for Stata to integrate Stata into an ag ...check
CVE-2026-47731The AMMOS Instrument Toolkit (Formerly the Bespoke Links to Instrument ...check
CVE-2026-49092Unintended Proxy or Intermediary ('Confused Deputy') (CWE-441) in Kiba ...check
CVE-2026-49294Valhalla is an open source routing engine and accompanying libraries f ...check
CVE-2026-53910diff3tool from GNU diffutilsis vulnerable to a heap\u2011based buffer ...check
CVE-2026-55223c3p0 is a JDBC Connection pooling library. In versions prior to 0.14.0 ...check if that is an issue with the packaged version
CVE-2026-55654A flaw was found in OpenSSH. This vulnerability, a heap out-of-bounds ...check details, AI generated report
CVE-2026-55655A flaw was found in OpenSSH. A local unprivileged attacker on a Linux ...check details, AI generated report
CVE-2026-55851Netty is a network application framework for development of protocol s ...check
CVE-2026-56146Improper Access Control (CWE-284) in Kibana can lead to unauthorized m ...check
CVE-2026-56147Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana c ...check
CVE-2026-56745Netty is a network application framework for development of protocol s ...check
CVE-2026-56746Netty is a network application framework for development of protocol s ...check
CVE-2026-56816Netty is a network application framework for development of protocol s ...check
CVE-2026-56817Netty is a network application framework for development of protocol s ...check
CVE-2026-56819Netty is a network application framework for development of protocol s ...check
CVE-2026-56820Netty is a network application framework for development of protocol s ...check
CVE-2026-56852A norm.Iter can enter an infinite loop when handling input containing ...check
CVE-2026-58050libssh2 through 1.11.1 reads an attacker-controlled 32-bit attribute c ...check with upstream, only affecting libssh2 on Winddows?
CVE-2026-58051libssh2 through 1.11.1 grows its publickey list with SSH2_REALLOC but ...check with upstream, only affecting libssh2 on Winddows?
CVE-2026-59674A UNIX Symbolic Link (Symlink) Following vulnerability in openSUSE Tum ...check
CVE-2026-59843A flaw was found in libssh. A remote authenticated peer can advertise ...check fixing commit in libssh-0.12.1

Search for package or bug name: Reporting problems