| Bug | Description | Note |
|---|
| CVE-2016-1584 | In all versions of Unity8 a running but not active application on a la ... | check proper tracking update |
| CVE-2022-23538 | github.com/sylabs/scs-library-client is the Go client for the Singular ... | check details, might as well affect golang-github-apptainer-container-library-client |
| CVE-2022-50942 | Incinga Web 2.8.2 contains a client-side cross-site scripting vulnerab ... | check status upstream |
| CVE-2023-26044 | react/http is an event-driven, streaming HTTP client and server implem ... | check, is embedded inicinga-php-thirdparty, icingaweb2-module-reactbundle possibly affected |
| CVE-2023-49316 | In Math/BinaryField.php in phpseclib 3 before 3.0.34, excessively larg ... | check if affecting ldap-account-manager or unused path |
| CVE-2023-50251 | php-svg-lib is an SVG file parsing / rendering library. Prior to versi ... | check, other packages are embedding the library: civicrm, icinga-php-thirdparty and icingaweb2 to be checked |
| CVE-2023-50252 | php-svg-lib is an SVG file parsing / rendering library. Prior to versi ... | check, other packages are embedding the library: civicrm, icinga-php-thirdparty and icingaweb2 to be checked |
| CVE-2023-50262 | Dompdf is an HTML to PDF converter for PHP. When parsing SVG images Do ... | check sources embedding php-dompdf if affected |
| CVE-2024-22420 | JupyterLab is an extensible environment for interactive and reproducib ... | check completeness, src:jupyter-notebook? |
| CVE-2024-22421 | JupyterLab is an extensible environment for interactive and reproducib ... | check completeness, src:jupyter-notebook? |
| CVE-2025-4382 | A flaw was found in systems utilizing LUKS-encrypted disks with GRUB c ... | double check if vulnerability only considered present after grub_is_cli_disabled is introduced |
| CVE-2025-6499 | A vulnerability classified as problematic was found in vstakhov libucl ... | check if impacts security wise rspamd, which embeds libucl and uses it a compile time |
| CVE-2025-8671 | A mismatch caused by client-triggered server-sent stream resets betwee ... | check, some projects will assign own CVEs and should then be covered under that specific CVE instead |
| CVE-2025-8941 | A flaw was found in linux-pam. The pam_namespace module may improperly ... | check likely RedHat specific incomplete fix for CVE-2025-6020, but asked to pinpoint incomplete fixes |
| CVE-2025-11010 | A vulnerability has been found in vstakhov libucl up to 0.9.2. Affecte ... | check if impacts security wise rspamd, which embeds libucl and uses it a compile time |
| CVE-2025-11147 | Reflected cross-site scripting (XSS) in Apt-Cacher-NG v3.2.1. The vuln ... | clarifying with reporter and Eduard Bloch on the issue. |
| CVE-2025-60796 | phpPgAdmin 7.13.0 and earlier contains multiple cross-site scripting ( ... | check, possibly not reported upstream |
| CVE-2025-60797 | phpPgAdmin 7.13.0 and earlier contains a SQL injection vulnerability i ... | check, possibly not reported upstream |
| CVE-2025-60798 | phpPgAdmin 7.13.0 and earlier contains a SQL injection vulnerability i ... | check, possibly not reported upstream |
| CVE-2025-60799 | phpPgAdmin 7.13.0 and earlier contains an incorrect access control vul ... | check, possibly not reported upstream |
| CVE-2025-61982 | An arbitrary code execution vulnerability exists in the Code Stream di ... | check upstream status |
| CVE-2025-67108 | eProsima Fast-DDS v3.3 was discovered to contain improper validation f ... | check https://gist.github.com/lkloliver/81b5d5a8328d712dbfd497bf11dbe913, unclear if reported upstream |
| CVE-2025-69534 | Python-Markdown version 3.8 contain a vulnerability where malformed HT ... | Asking whether it really needs a backport: https://bugs.debian.org/1131896 |
| CVE-2025-69720 | The infocmp command-line tool in ncurses before 6.5-20251213 has a sta ... | check upstream status |
| CVE-2026-0708 | A flaw was found in libucl. A remote attacker could exploit this by pr ... | check if impacts security wise rspamd, which embeds libucl and uses it a compile time |
| CVE-2026-1703 | When pip is installing and extracting a maliciously crafted wheel arch ... | check as well pipenv |
| CVE-2026-4833 | A weakness has been identified in Orc discount up to 3.0.1.2. This iss ... | check libtext-markdown-discount-perl, ruby-rdiscount, cantor, embedding discount; check if security impact present |
| CVE-2026-5422 | A path traversal vulnerability exists in jupyter-server version 2.17.0 ... | CNA contacted responsible for this CVE entry as this seems to be a duplicate of CVE-2026-35397 |
| CVE-2026-6657 | A vulnerability in jupyter-server versions 1.12.0 through 2.17.0 allow ... | CNA contacted responsible for this CVE entry as this seems to be a duplicate of CVE-2026-40110 |
| CVE-2026-7701 | A security vulnerability has been detected in Telegram Desktop up to 6 ... | check upstream reports |
| CVE-2026-7790 | Uncontrolled Resource Consumption vulnerability in ninenines cowlib (c ... | check if embedded copy in rabbitmq-server is problematic |
| CVE-2026-8851 | SOGo versions 5.12.7 and prior contains a SQL injection vulnerability ... | check correctness |
| CVE-2026-10051 | In Eclipse Jetty, a first HTTP/1.1 request with trailers causes the se ... | check, jetty9 might not be affected as not explicitly mentioned in the GhSA and still supported |
| CVE-2026-10528 | A security flaw has been discovered in Orthanc DICOM Server up to 1.12 ... | check, uderlying issue in src:dcmtk and should the CVE be associated with it? Cf. #1138713 |
| CVE-2026-12611 | A client may issue HTTP/2 requests to a Jetty server that result in bl ... | check, GHSA reference not yet public |
| CVE-2026-15779 | A flaw was found in samba's pam_winbind. When mkhomedir is enabled, pa ... | check if Red Hat specific |
| CVE-2026-18358 | A flaw was found in gnome-remote-desktop as shipped in Red Hat Enterpr ... | does not affect an upstream version, but need to check if still only Red Hat specific, check details RH bug |
| CVE-2026-19201 | An uncontrolled recursion vulnerability in the Windows SIPA event log ... | check, GHSA not yet public, maybe Windows specific |
| CVE-2026-19203 | A client may issue specially crafted HTTP/1.1 chunked requests to a Je ... | check, GHSA reference not yet public |
| CVE-2026-19204 | A client may send a WebSocket frame with an unknown opcode and a very ... | check, GHSA reference not yet public |
| CVE-2026-19614 | The API is prone to XML external entity (XXE) injection. By default, X ... | check details as reference not accessible |
| CVE-2026-23479 | Redis is an in-memory data structure store. In redis-server from 7.2.0 ... | check redict and valkey |
| CVE-2026-23631 | Redis is an in-memory data structure store. In all versions of redis-s ... | check redict and valkey |
| CVE-2026-25243 | Redis is an in-memory data structure store. In versions of redis-serve ... | check redict and valkey |
| CVE-2026-27970 | Angular is a development platform for building mobile and desktop web ... | check status for older versions |
| CVE-2026-29022 | dr_libs dr_wav.h version 0.14.4 and earlier (fixed in commit 8a7258c) ... | qtads, dosbox-x, roc-toolkit, octave-ltfat, faudio bundle a copy, check security impact |
| CVE-2026-29036 | cJSON versions 1.5.0 through 1.7.19 contain an incorrectly-resolved na ... | check, report upstream status |
| CVE-2026-32635 | Angular is a development platform for building mobile and desktop web ... | check status for older versions |
| CVE-2026-36499 | A missing upper-bound check in the udpif_set_threads() function of Ope ... | check, unclear status/validity |
| CVE-2026-39178 | A SQL injection vulnerability in SOGo before 5.12.7 allows authenticat ... | CVE-2026-39178 and CVE-2026-39179 are duplicates of CVE-2026-46445 and CVE-2026-46446, CNA contacted |
| CVE-2026-39179 | A SQL injection vulnerability in SOGo before 5.12.7 allows authenticat ... | CVE-2026-39178 and CVE-2026-39179 are duplicates of CVE-2026-46445 and CVE-2026-46446, CNA contacted |
| CVE-2026-39860 | Nix is a package manager for Linux and other Unix systems. A bug in th ... | check, potentially affecting guix if same issue in backporting fix for CVE-2024-2729 |
| CVE-2026-40033 | FreeRDP before 3.26.0 contains a heap-buffer-overflow vulnerability in ... | unclear fixing commit references, incorrect reference in CVE entry? |
| CVE-2026-41889 | pgx is a PostgreSQL driver and toolkit for Go. Prior to version 5.9.2, ... | check the other golang-github-jackc-pgx* sources |
| CVE-2026-42308 | Pillow is a Python imaging library. Prior to version 12.2.0, if a font ... | research fixing commit(s), maybe https://github.com/python-pillow/Pillow/pull/9518/changes |
| CVE-2026-42503 | gopls by default communicates via pipe. However, -port and -listen fla ... | check impact on golang-golang-x-tools |
| CVE-2026-48809 | python-engineio is a Python implementation of the Engine.IO realtime c ... | checking upstream commit fixing issue, confusing infomation advisory claims both 4.13.2 and 4.13.5 to fix issue |
| CVE-2026-51400 | An issue in Vim Project v9.2.0389 and earlier allows a local attacker ... | check, possibly not reported upstream, only reporter reference in github gist |
| CVE-2026-51401 | An issue in Vim Project v9.2.0389 and earlier allows a local attacker ... | check, possibly not reported upstream, only reporter reference in github gist |
| CVE-2026-55223 | c3p0 is a JDBC Connection pooling library. In versions prior to 0.14.0 ... | check if that is an issue with the packaged version |
| CVE-2026-56684 | Valkey is a distributed key-value database. Prior to 7.2.14, 8.0.10, 8 ... | check redis and redict |
| CVE-2026-56816 | Netty is a network application framework for development of protocol s ... | check, potentially only in 4.2.y series |
| CVE-2026-56818 | Netty is an asynchronous, event-driven network application framework. ... | check missing upstream GHSA |
| CVE-2026-57862 | Kanboard 1.2.52 and prior contains a server-side request forgery vulne ... | check upstream report |
| CVE-2026-61711 | BuildKit is a toolkit for converting source code to build artifacts in ... | check security impact on docker.io |
| CVE-2026-61712 | BuildKit is a toolkit for converting source code to build artifacts in ... | check potential security impact on docker.io |
| CVE-2026-63639 | Valkey is a distributed key-value database. Prior to 7.2.14, 8.0.10, 8 ... | check redis and redict |
| CVE-2026-64611 | A flaw was found in libcupsfilters. The cfIEEE1284NormalizeMakeModel() ... | check use in embedded cups, cups-filters |
| CVE-2026-68006 | An issue in Puma v.5.0.0 and before v.8.0.3 allows an attacker to exec ... | check, unclear if https://github.com/czx1111/cve/issues/1 properly reported upstream |
| CVE-2026-71219 | A stack overflow vulnerability was found in gfs2-utils. The hash table ... | check upstream details |
| CVE-2026-71220 | A stack out-of-bounds write vulnerability was found in gfs2-utils. In ... | check upstream details |
| CVE-2026-71221 | A stack out-of-bounds write vulnerability was found in gfs2-utils. In ... | check upstream details |
| CVE-2026-71222 | A heap out-of-bounds read vulnerability was found in gfs2-utils. The e ... | check upstream details |
| CVE-2026-71224 | A stack overflow vulnerability was found in gfs2-utils. The metadata w ... | check upstream details |
| CVE-2026-71261 | dr_libs dr_wav.h (all versions through current master) contains an int ... | check if embedded copy has security impact in roc-toolkit, qtads, qt6-multimedia, octave-ltfat, raylib, dosbox-x, mlpack and faudio |
| CVE-2026-71287 | Cacti's sanitize_sql_column (lib/functions.php) sanitizes user-supplie ... | check, assigned from "Turan Security" CNA without further detailed references |
| CVE-2026-71437 | Mermaid is a JavaScript tool that uses Markdown-inspired text to creat ... | check introducing commit for further assessment |
| CVE-2026-71439 | Mermaid is a JavaScript tool that uses Markdown-inspired text to creat ... | check introducing commit, might then be only 11.6.0 and above. |
| CVE-2026-72556 | A remote code execution vulnerability in ZoneMinder 1.39.17 allows any ... | check, another CVE assigned by "Turan Security" CNA without providing details |
| CVE-2026-75593 | BuildKit is a toolkit for converting source code to build artifacts in ... | check security impact on docker.io |
| CVE-2026-76925 | A flaw was found in Flatpak. A Time-of-check to time-of-use (TOCTOU) r ... | check, CNA contacted for getting more information |
| CVE-2026-82631 | A security flaw has been discovered in valkey-io valkey 9.1.0. The aff ... | check resis and restic |
| CVE-2026-82677 | A vulnerability was determined in valkey-io valkey 9.1.0. Impacted is ... | check redis, restic? |
| CVE-2026-84233 | A flaw was found in rpm. A local attacker could supply a specially cra ... | check upstream details |
| CVE-2026-85150 | A NULL pointer dereference flaw was found in GStreamer's RTSP support ... | double-check, the MR is still not public, but advisory states fixed in 1.28.7 |
| CVE-2026-86776 | KeePass versions 2.35 through 2.61.1 fail to validate KDBX header fiel ... | check upstream details |
| CVE-2026-87020 | An integer overflow in a specified pitch and buffer-size computation l ... | check, might be a dupe of the existing issues addressed in 1.13, needs clarification |
| CVE-2026-90648 | wasm2c in WebAssembly wabt through 1.0.41 allows sandbox escape in som ... | check upstream details |
| TEMP-1142597-FFA22A | GHSA-68ff-gq39-pqjm: relay: authentication bypass with the "plain" password hash algorithm | check, GHSA-68ff-gq39-pqjm claims >= 4.3.0 but potentially since v2.9-rc1 |