Security advisories — page 5
- CVE-2026-54690highCVE-2026-54690 updated by NVD
- CVE-2026-54691highCVE-2026-54691 updated by NVD
- CVE-2026-54705mediumCVE-2026-54705 updated by NVD
- CVE-2026-10720mediumCanonical MicroCeph: path traversal issue in the remote-import AP
- CVE-2026-11529lowCVE-2026-11529 updated by NVD
- CVE-2026-52809mediumGogs's password-reset tokens use account-activation lifetime, ignoring RESET_PASSWORD_CODE_LIVES
- CVE-2026-58424highGitea: Permanent Fork PR Workflow Approval Gate Bypass
- CVE-2026-47304highCVE-2026-47304 updated by NVD
- CVE-2026-7776highHashicorp Boundary workers are vulnerable to a denial-of-service condition during node enrollment TLS handshak
- CVE-2026-63118mediumCVE-2026-63118 updated by NVD
- CVE-2026-53467mediumImageMagick: Information Disclosure in MNG decoder because allocated memory is left unchanged
- CVE-2026-8384mediumEclipse Jetty: Path parameter traversal
- CVE-2026-41839mediumCVE-2026-41839 updated by NVD
- CVE-2026-6790mediumEclipse Jetty: HTTP Authority/Host mismatch
- CVE-2026-65902mediumCVE-2026-65902 updated by NVD
- CVE-2026-55391highCVE-2026-55391 updated by NVD
- CVE-2026-50132highBudibase has an Account Impersonation Issue — Chat Identity Link Hijacking via Missing Consent & CSRF
- CVE-2026-46428criticalCVE-2026-46428 updated by NVD
- CVE-2026-59896mediumhono/jsx does not isolate context per request, leading to cross-request data disclosure
- CVE-2026-59895mediumHono: Server-Side XSS via JSX Escaping Bypass in cx() Utility
- CVE-2026-52840lowEasy!Appointments has server-side request forgery in CalDAV connection test that exposes the deployment's inte
- CVE-2026-59882mediumguzzlehttp/psr7: Host Confusion via Weak URI Host Validation
- CVE-2026-54287mediumhono: AWS Lambda adapter merges multiple `Set-Cookie` headers into one value, dropping cookies on ALB single-h
- CVE-2026-41853mediumCVE-2026-41853 updated by NVD
- CVE-2026-65903mediumCVE-2026-65903 updated by NVD
- CVE-2026-55651highEasy!Appointments Vulnerable to Appointments Takeover via Excessive Data Exposure
- CVE-2026-52838lowEasy!Appointments disable_booking_message rendered as raw HTML on public booking page — Stored XSS
- CVE-2026-45293highCVE-2026-45293 updated by NVD
- CVE-2026-53925highGlances has arbitrary file write and command execution via `secure_popen` redirection and chaining operators i
- CVE-2026-54663mediumCVE-2026-54663 updated by NVD
- CVE-2026-64785mediumCVE-2026-64785 updated by NVD
- CVE-2026-49756lowCVE-2026-49756 updated by NVD
- CVE-2026-65913mediumCVE-2026-65913 updated by NVD
- CVE-2026-58426criticalGitea Actions Artifacts V4 signed URL HMAC ambiguity allows cross-repository artifact read and cross-task uplo
- CVE-2026-41852lowCVE-2026-41852 updated by NVD
- CVE-2026-54557mediummise HTTP backend uses raw version path for install symlink destination
- CVE-2026-54096highFile Browser: Improper Access Control Occurs via Pre-Created Public Share for a Non-existent Path
- CVE-2026-41715mediumCVE-2026-41715 updated by NVD
- CVE-2026-41838mediumCVE-2026-41838 updated by NVD
- CVE-2026-65900mediumCVE-2026-65900 updated by NVD
- CVE-2026-65912mediumCVE-2026-65912 updated by NVD
- CVE-2026-59253mediumn8n: Improper Authorization Allows Authenticated Users to Assign Workflows to Folders in Other Projects
- CVE-2026-41847mediumCVE-2026-41847 updated by NVD
- CVE-2026-41845highCVE-2026-41845 updated by NVD
- CVE-2026-11479lowCVE-2026-11479 updated by NVD
- CVE-2026-50526highCVE-2026-50526 updated by NVD
- CVE-2026-46611mediumGlances: XML-RPC Server Missing Host Header Validation Enables DNS Rebinding Attack
- CVE-2026-65898mediumCVE-2026-65898 updated by NVD
- CVE-2026-65901mediumCVE-2026-65901 updated by NVD
- CVE-2026-28377highGrafana Tempo has Inadequate Encryption Strength
- CVE-2026-54656highCVE-2026-54656 updated by NVD
- CVE-2026-54545highCVE-2026-54545 updated by NVD
- CVE-2026-52839lowCVE-2026-52839 updated by NVD
- CVE-2026-54574highCVE-2026-54574 updated by NVD
- CVE-2026-54655highCVE-2026-54655 updated by NVD
- CVE-2026-59208highn8n: Cross-Issuer Token Exchange Account Binding via Subject-Only Identity Resolution
- CVE-2026-54654highCVE-2026-54654 updated by NVD
- CVE-2026-54621highCVE-2026-54621 updated by NVD
- CVE-2026-41846mediumCVE-2026-41846 updated by NVD
- CVE-2026-41844mediumCVE-2026-41844 updated by NVD
- CVE-2026-54639highStyle Dictionary - Prototype Pollution in convertTokenData utility function
- CVE-2026-54605highCVE-2026-54605 updated by NVD
- CVE-2026-16584highCVE-2026-16584 updated by NVD
- CVE-2026-63119mediumCVE-2026-63119 updated by NVD
- CVE-2026-52841lowEasy!Appointments: Authorization bypass in Google OAuth provider binding lets any backend user rebind a peer p
- CVE-2026-54672highelectron-updater: Uncontrolled search path elements within `AppImage` built by `app-builder-lib`
- CVE-2026-59897mediumHono: API Gateway v1 adapter can drop a distinct repeated request header value during de-duplication
- CVE-2026-49356low@babel/core: Arbitrary File Read via sourceMappingURL Comment
- CVE-2026-54727highCVE-2026-54727 updated by NVD
- CVE-2026-13769mediumAWS CLI: Overly permissive File Permissions
- CVE-2026-50568lowFission: SanitizeFilePath lexical HasPrefix bypass permits sibling-directory escape
- CVE-2026-54289mediumhono: Lambda@Edge adapter keeps only the last value of a repeated request header, dropping the rest
- CVE-2026-44018mediumDocling: Unsafe Archive Extraction and XML Parsing in METS-GBS Backend
- CVE-2026-54620lowCVE-2026-54620 updated by NVD
- CVE-2026-54619lowCVE-2026-54619 updated by NVD
- CVE-2026-55597mediumImageMagick: Heap Buffer Over-Write in JP2 encoder when due to incorrect handling of arguments
- CVE-2026-55510mediumImageMagick: Use-After-Free in crafted 8BIM when identifying an image
- CVE-2026-54288mediumhono: Body Limit Middleware can be bypassed on AWS Lambda by understating `Content-Length`
- CVE-2026-55628mediumCVE-2026-55628 updated by NVD
- CVE-2026-55595mediumImageMagick: Infinite Loop in connected-components when providing invalid arguments
- CVE-2026-11481lowCVE-2026-11481 updated by NVD
- CVE-2026-53765mediumChrome DevTools for agents: daemon.pid write follows symlinks in /tmp fallback runtime directory
- CVE-2026-66066criticalCVE-2026-66066 updated by NVD
- CVE-2026-54522lowCVE-2026-54522 updated by NVD
- CVE-2026-54722highCVE-2026-54722 updated by NVD
- GHSA-pmwx-rm49-xv39lowActiveRecord::Tenanted::Storage::DiskService#path_for has a possible path traversal
- GHSA-xvg2-cgv6-6h7vhighnetfoil: Incorrect block responses could lead to localhost traffic
- GHSA-wchh-9x6h-7f6pmediumolm dependency deprecation: CVE-2022-39255 and CVE-2024-45193
- GHSA-pc2w-4mq8-32qwlow@dynatrace-oss/dynatrace-mcp-server's create_dynatrace_notebook missing the human-approval gate
- GHSA-6xx4-9wp6-65p7mediumskilo add follows symbolic links, allowing arbitrary local file disclosure from a malicious skill source
- CVE-2026-49446mediumCosmos-Server has an authentication bypass via forward-auth header smuggling on Constellation tunnel
- CVE-2026-54632highSIPSorcery: Malformed UDP packet on the RTP/ICE socket can remotely terminate a media session (DoS)
- GHSA-hc4m-q9jh-xw4jmediumnono-cli'scregistry pack verification can fail open when provenance metadata is absent
- GHSA-vg6v-j97m-h5xqmedium@novu/application-generic: `validateUrlSsrf` permits CGNAT (100.64.0.0/10) destinations — affects Workflow HTT
- GHSA-hp74-gm6m-2qm5mediumPocket ID has a reauthentication bypass via one-time access token login — passkey step-up requirement defeated
- CVE-2023-37465mediumorg.xwiki.contrib:discussions-server has Cross-Site Request Forgery (CSRF) issue that makes it possible to del
- GHSA-6vch-q96h-7gc3highetcd: `tlsListener.acceptLoop` spawns unbounded handshake goroutines with no deadline
- GHSA-8q49-2h5h-434xmediumFrontMCP: Server-Side Request Forgery (SSRF) in the OpenAPI adapter spec-change poller
- GHSA-jpcw-4wr7-c3vqmediumkin-openapi openapi3filter: unauthenticated nil-pointer panic when validating a request against a `content` pa
- GHSA-xg4h-6gfc-h4m8highetcd: Watch API authorization bypass via open-ended range requests
- GHSA-hmj8-5xmh-5573highlibp2p: yamux connection DoS via oversized data frame
- GHSA-3r53-75j5-3g7jmediumQuasar: Prototype pollution in the extend() utility
- GHSA-6xj8-qv9j-xcjqhighOh My Posh: Arbitrary command execution via template injection in the path segment
- GHSA-fwjx-9p69-h25hmediumOh My Posh: Terminal escape sequence injection via unsanitized prompt segment data
- GHSA-fp43-vj7g-pg92highOmniFaces: Forged combined-resource IDs and related output/push boundaries
- GHSA-gm3r-q2wp-hw87highShescape: Quadratic-time denial of service in the flag-protection
- GHSA-q53c-4prm-w95qmediumShescape: Home-directory disclosure in assignment context on Unix with Dash
- GHSA-w4hw-qcx7-56prcriticalShescape: Shell injection via unescaped parentheses on Windows with CMD
- GHSA-6v4m-fw66-8r4xmediumShescape: Path disclosure on Unix with Zsh
- GHSA-86cx-wwf4-phq4mediumOpenList: Arbitrary File Read via Path Prefix Confusion in Share Creation API
- GHSA-p6ph-3jx2-3337mediumOpenList: Search metadata/count disclosure via Non-Separator-Aware Path Check in Bleve Search
- GHSA-95cv-r8x4-vh75highOpenList: Authenticated users can rename files outside their base path via batch rename `src_name` traversal
- GHSA-7ppr-r889-mcf2highblaze: Unbounded WebSocket message aggregation in http4s-blaze-server
- GHSA-46q4-43ph-c6frhighblaze: Chunked-body trailer fields promoted into Request.headers in blaze-server (front-end header-sanitizatio
- GHSA-mhvj-jhpq-885vhighblaze: Multiple HTTP/1.1 request-smuggling primitives in blaze's Java wire parser
- GHSA-cmwh-g2h8-c222highPoweradmin: OIDC `sub` collation bypass in Poweradmin leading to account takeover
- GHSA-rm67-g9ch-vxffhighPoweradmin: Broken access control (IDOR): any zone owner can modify DNS records in zones they do not own
- GHSA-h4hf-v6w5-897xhighPoweradmin: API user-update endpoint leads to a non-admin reset any user's password and take over the superuse
- GHSA-f25v-x6vr-962gcriticalPheditor: Authentication Bypass in Forced Password-Change Flow via Unverified Current Password
- GHSA-vh45-f885-3848criticalsm-crypto: Predictable SM2 key generation in Node.js: default RNG uses Math.random + wall clock
- GHSA-v6w6-358x-2433mediumCloudreve Admin.Read OAuth tokens can trigger server-side node test requests
- GHSA-47w6-gwp4-w6vchighvantage6: Algorithm developer can edit another developer's algorithm that is pending / under review
- GHSA-2625-rw7m-5q5xlowHubuum client library (Rust): Sensitive data may be exposed through default diagnostics
- GHSA-qqc3-94qv-7fw3mediumHubuum client library (Rust): Configured custom transports may be bypassed, exposing credentials and network t
- GHSA-f45q-w629-wr25mediumHubuum client library (Rust): Authenticated requests may escape the configured base path through redirects
- GHSA-26gq-p25f-99cphighfrp: Unauthenticated Remote Denial of Service in the frp SSH Tunnel Gateway via Integer Overflow
- GHSA-g5vv-q72c-7j78high@anephenix/hub: Unauthenticated WebSocket RPC Waiter Resource Exhaustion
- GHSA-c534-2w9c-x7fmmediumKite Kubernetes proxy path traversal allows authenticated users to bypass RBAC and read cluster-wide resources
- GHSA-p279-2cqp-84jgcriticalOpenDJ SASL PLAIN authzid bypassing the proxy ACI scope check
- GHSA-68r5-9hpg-7qw9criticalOpenDJ unauthenticated SSRF, local file read and unbounded-read DoS in the DSMLv2 gateway
- GHSA-g3hq-hphg-8fhhhighPheditor: Terminal command-allowlist bypass via argument injection leads to RCE — surviving vector after the m
- GHSA-94p4-4cq8-9g67highGitPython: Environment-variable exfiltration via Repo.create_remote() / Remote.add() URL (incomplete fix of GH
- GHSA-hfhx-w8p8-4hc7mediumBudibase: SSRF via bare fetch() in uploadUrl during AI table generation
- GHSA-v42f-v8xc-j435highBudibase: SSRF via DNS rebinding in the REST datasource integration
- GHSA-pmpg-2mxq-6xwrhighBudibase: NoSQL injection in MongoDB integration: collection dump, $where JS exec, cross-collection pivot, arb
- GHSA-cr7p-cr3q-h5cmmediumBudibase: Account Enumeration via Login Lockout Response Differential
- GHSA-pvcr-8mvp-w8qrhighBudibase: Chat-Link Handoff Identity Confusion (Same-Tenant Account-Link CSRF)
- GHSA-2xgg-r2wc-c5r2highBudibase: MySQL DESCRIBE Backtick Injection via multipleStatements in Database Connector
- GHSA-qw6m-8fw2-2v64highBudibase: NoSQL Injection via JSON Parameter Interpolation in MongoDB Query Execution
- GHSA-gh4h-34gr-87r7mediumBudibase: OAuth2 Token Disclosure via Automation Test Results Broadcast to Other Builders
- GHSA-hr66-5mqr-8mpxhighBudibase: Unauthenticated user information disclosure via public tenant user lookup endpoint
- GHSA-mqhr-6j6h-74p5criticalBudibase: Unauthenticated REST Datasource Credential Theft via Cross-Origin Auth Leak
- CVE-2026-62323mediumCloudreve WOPI view sessions can write files and WOPI access token secret is ignored
- GHSA-hp6v-6jw7-gv2fcriticalBudibase: OIDC SSO account takeover: incoming identity linked by email without checking email_verified
- GHSA-xg5g-26x8-cvf4highBudibase: DNS rebinding SSRF bypasses remain in OpenAPI import and REST query execution
- GHSA-xcx6-4f2g-hhgxhighBudibase: S3 presigned URL endpoint authorization regression in v3.39.4 allows BASIC users to obtain S3 PutObj
- GHSA-ppr4-5f46-j9c6highBudibase: Server Filesystem Existence/Read Oracle via Builder-Controlled MongoDB tlsCertificateKeyFile
- GHSA-q6x4-v3qx-85qwcriticalBudibase: SQL Injection via `multipleStatements: true`
- GHSA-c8vc-7pv3-g98phighBudibase: Email Change IDOR via POST /api/v2/email allows full Account Takeover (accountId not validated again
- GHSA-fcrw-f7gg-6g9fmediumBudibase: SSO OAuth2 Token Leakage via User Metadata Endpoints to Power-Role Users
- GHSA-4qcj-m5wp-jmf4mediumBudibase: Missing RBAC on GET /api/global/groups allows BASIC users to enumerate all tenant groups and role ma
- GHSA-j9fc-w3mr-x6mvhighBudibase: Privilege escalation via public role assignment API missing app-level authorization
- CVE-2026-62379criticalOpenAM: Unauthenticated Remote Code Execution via Class.forName in AuthXMLUtils.createCustomCallback
- CVE-2026-62280mediumOpenAM Reflected XSS in the OAuth2/OIDC `wap` consent page
- CVE-2026-62263criticalOpenAM: WebAuthn Java deserialization RCE via ObjectInputFilter depth>1 bypass
- CVE-2026-57497mediumwebtransport-go: Memory Exhaustion Attack due to Buffering of Unknown Capsules
- CVE-2026-55502highCloudreve OAuth Admin.Read scope can update OneDrive storage policy credentials
- CVE-2026-55499mediumCloudreve: Broken Access Control in file event stream: a single-file share recipient is subscribed to the owne
- CVE-2026-55497mediumCloudreve: Denial of Service - Image decompression / pixel bomb in thumbnail & avatar decoding crashes the
- CVE-2026-55496mediumCloudreve: Information Exposure in `GET /api/v4/user/search`: `SearchActive` omits the active-status predicate
- CVE-2026-55495mediumCloudreve: Path Traversal in WOPI PUT_RELATIVE Allows Arbitrary File Creation in Owner Account
- CVE-2026-59714highOpen WebUI: Cross-channel message overwrite via chat completion API (single-model and multimodel message_ids)
- GHSA-v74w-7mr3-4qg3highNetty: Denial of Service in XmlFrameDecoder via CPU Exhaustion
- GHSA-mfg7-5gfp-c4w3mediumNetty: Memory Leak in DNS Record Decoder via Malformed Domain Names
- GHSA-r277-6w6q-xmqwcriticalkin-openapi: ValidationHandler.Load() Fail-Open Authentication Bypass via NoopAuthenticationFunc Default
- GHSA-gcjh-h69q-9w9gmediumcel-go: JSON Private Fields Exposed via NativeTypes and ParseStructTag
- GHSA-pm4m-ph32-ghv5highjs-yaml: Exponential parsing time in flow collections leads to denial of service
- GHSA-g9hv-x236-4qp3mediumRussh: client wrong-length X25519 `clone_from_slice` panic (pre-auth DoS)
- GHSA-cqjc-rmpq-xprqmediumRussh: Post-auth remote panic via pty-req with more than 130 terminal-mode records
- GHSA-5xvq-cp9x-6p6rmediumRussh: Pre-auth remote panic via all-zero Curve25519 peer public value (encode_mpint OOB)
- GHSA-qwww-vcr4-c8h2highReact Router: RSC Mode CSRF Bypass Allows Action Execution Before 400 Response
- GHSA-464c-974j-9xm6lowAWS CDK CodeBuild S3 Log Encryption Boolean Inversion
- GHSA-r9mr-m37c-5fr3highGitPython: Unsafe git option guard bypass via single-character kwarg value token smuggling enables arbitrary c
- GHSA-6p8h-3wgx-97gfhighGitPython: Incomplete unsafe_git_clone_options denylist omits --template enabling arbitrary command execution
- GHSA-fjr4-x663-mwxchighGitPython: Arbitrary file overwrite via git diff --output argument injection in Diffable.diff (key- and value-
- GHSA-r292-9mhp-454mmediumnode-tar: Uncontrolled recursion in mapHas/filesFilter allows uncatchable stack-overflow DoS via crafted long-
- GHSA-r28c-9q8g-f849highPostCSS: Path Traversal in Previous Source Map Auto-Loading (sourceMappingURL) leads to Arbitrary .map File Di
- GHSA-w28w-gp39-m4p6criticalPrompty: Server-Side Template Injection to Remote Code Execution in the @prompty/core Nunjucks Renderer
- GHSA-664h-wqgq-64gwmediumMongoose: Prototype pollution in mongoose update casting via __proto__-prefixed dotted path (Schema._getSchema
- GHSA-3rp5-jjmw-4wv2highGitPython: git-config section-name injection enables arbitrary config directives (core.sshCommand RCE)
- GHSA-7gfh-x38p-prh3criticalVelocity.js: Remote Code Execution via property-read to Function constructor (bypass of GHSA-j658-c2gf-x6pq fi
- GHSA-38hq-7x33-php4medium@backstage/plugin-auth-backend: Unauthenticated OAuth account takeover via `redirect_uri` allowlist bypass
- CVE-2026-62946mediumCVE-2026-62946 updated by NVD
- CVE-2026-62363mediumCVE-2026-62363 updated by NVD
- CVE-2026-62343mediumCVE-2026-62343 updated by NVD
- CVE-2026-61632mediumPyMdown Extensions: Path traversal in the b64 extension lets read files outside base_path
- GHSA-53g2-mvcc-q9x3mediumTrix: Stored XSS via HTMLParser attribute injection on paste
- GHSA-p5rm-jg5c-8c77mediumMicrosoft Kiota: Path traversal in generated plugin manifest static_template.file reference (percent-encoding
- CVE-2026-59952mediumCVE-2026-59952 updated by NVD
- CVE-2026-59940criticalseroval: `seroval.fromJSON()` Promise resolver type confusion invokes attacker-controlled methods during deser
- CVE-2026-59949mediumLZ4 Java: Native XXHash implementations can crash the JVM when passed invalid byte array ranges
- GHSA-866w-xmhq-wj7xmediumSvelteKit: Prototype pollution in file input deletion path in remote-function forms
- GHSA-wqjv-9729-c5q2mediumSvelteKit: Big remote form function payloads can cause Node process to crash
- CVE-2026-63632lowONNX: Heap-Buffer-Overflow READ in Gemm Version Converter Adapter via Undersized Input Shape
- GHSA-qq9h-g4jm-xgf3highBetter Auth: Account takeover via pre-account hijacking on magic-link and email-OTP sign-in
- GHSA-h3rm-78g3-j7cphigh@better-auth/stripe: cross-organization billing tampering in organization subscription actions
- GHSA-rjg6-39jm-rgg4critical@better-auth/scim: account takeover and stale access via SCIM provider-id collision
- GHSA-76q6-2p6h-xjqrlowImageMagick: Heap Buffer Over-Write in X11 import with crafted window title
- GHSA-h5r4-w88w-7ccrlowImageMagick: Memory Leak in TIFF encoder when invalid tiff:tile-geometry is specified
- GHSA-h58x-r7f7-rh84lowImageMagick: Memory Leak in ICON decoder when allocation fails
- GHSA-m596-67p7-69whlowImageMagick: Memory leak in VIFF encoder when allocation fails
- GHSA-r628-69v2-2f9clowImageMagick: Memory Leak in MIFF encoder when allocaton fails
- GHSA-h7f2-f9cc-h2gvlowImageMagick: Memory Leak in YUV decoder when opening of blob fails
- GHSA-jfq9-q63x-rc63lowImageMagick: Memory Leak in TIFF encoder when an allocation fails
- GHSA-99w9-hv66-rfv7lowImageMagick: Memory Leak in JNG encoder when a blob could not be opened
- GHSA-j8rh-v2r8-v94xlowImageMagick: Memory Leak in hough lines operation when an operation fails
- GHSA-7c7m-fpjw-gwcqlowImageMagick: Memory Leak in color transformation to log colorspace when operation fails
- GHSA-6vxp-gfwf-hcr9lowImageMagick: Memory Leak in TIFF encoder when a temporary file could not be created.
- GHSA-hwf3-r46v-5ggxlowImageMagick: Information Disclosure when printing profiles with debug enabled
- GHSA-qvxh-prvr-85w2lowImageMagick: Use-After-Free in FormatMagickCaption when memory allocation fails
- GHSA-6jwg-7q3p-5fqmlowImageMagick: Use-After-Free when freetype initialization fails
- GHSA-vghg-5jrg-2398lowImageMagick: Policy Bypass in script operation due to missing checks
- GHSA-v3j6-27vc-7pw2lowImageMagick: Policy Bypass in APNG encoder and delegates due to a missing check
- GHSA-qh5g-q395-cx4jlowImageMagick: Heap-use-after-free via XMP profile could result in a crash
- GHSA-hc76-7mpc-qjqhmediumImageMagick: Code injection in HTML encoder due to incomplete fix of CVE-2026-25797
- GHSA-56m6-8q75-f2rwmediumImageMagick: Policy Bypass due to an incomplete fix of CVE-2026-49219
- GHSA-rvhp-75f6-9jqhlowImageMagick: Policy Bypass possible with matrix-backed operations
- GHSA-4w2j-m93h-cj5jhighQuinn: Remote memory exhaustion in quinn-proto from unbounded out-of-order stream reassembly
- CVE-2026-55685highCVE-2026-55685 updated by NVD
- CVE-2026-53669mediumCVE-2026-53669 updated by NVD
- CVE-2026-53668mediumCVE-2026-53668 updated by NVD
- CVE-2026-53667mediumCVE-2026-53667 updated by NVD
- CVE-2026-53666mediumCVE-2026-53666 updated by NVD
- CVE-2026-47219highCVE-2026-47219 updated by NVD
- CVE-2026-45623highCVE-2026-45623 updated by NVD
- CVE-2026-59933highCVE-2026-59933 updated by NVD
- CVE-2026-59932highCVE-2026-59932 updated by NVD
- CVE-2026-59931highCVE-2026-59931 updated by NVD
- GHSA-8fpg-xm3f-6cx3criticalAuth.js: Configuration errors can cause existence-based auth checks to fail open (auth object populated with a
- GHSA-xmf8-cvqr-rfgjhighAuth.js: getToken() throws an uncaught exception on malformed Bearer authorization headers
- GHSA-7rqj-j65f-68whcriticalAuth.js: Email normalizer validates the address before Unicode normalization, allowing a homoglyph @ bypass
- GHSA-x445-f3h2-j279mediumAuth.js: OAuth state, nonce, and PKCE check cookies are not bound to the provider that created them
- GHSA-652q-gvq3-74qvmediumn8n: Snowflake Node executeQuery Operation Allows SQL Injection via Unparameterized Expression Interpolation
- GHSA-jqwr-vx3p-r266mediumn8n: PostgresTrigger Node SQL Injection Allows Authenticated Users to Execute Arbitrary SQL on Connected Postg
- GHSA-9cmh-xcqm-5hqrmediumn8n: Cross-Tenant Module-Cache Poisoning in the JS Task Runner
- GHSA-pppj-hq3g-57pjhighJupyterLab: Cross-site scripting (XSS) via crafted settings file (`overrides.json`)
- GHSA-gx64-gj6p-pc4chighJupyterLab: Image viewer allows XSS when opening malicious image in new browser tab
- GHSA-89vp-jrxv-24w8mediumJupyterLab: PyPI extension blocklist package-name canonicalization bypass
- GHSA-h5v5-8746-g7mmmediumJupyterLab PluginManager lock-rule enforcement bypass
- GHSA-whvh-wf3x-g77jlowJupyterLab: Allowlist/blocklist check in `PyPIExtensionManager.install()` not enforced for direct callers (mis
- CVE-2026-64649highCVE-2026-64649 updated by NVD
- CVE-2026-64648mediumCVE-2026-64648 updated by NVD
- CVE-2026-64647mediumCVE-2026-64647 updated by NVD
- CVE-2026-64646mediumCVE-2026-64646 updated by NVD
- CVE-2026-64645highCVE-2026-64645 updated by NVD
- CVE-2026-64644mediumCVE-2026-64644 updated by NVD
- CVE-2026-64643mediumCVE-2026-64643 updated by NVD
- CVE-2026-64642highCVE-2026-64642 updated by NVD
- CVE-2026-64641highCVE-2026-64641 updated by NVD
- CVE-2026-10050highEclipse Jetty Digest Authentication: ISO-8859-1 lossy encoding allows authentication bypass via character subs
- CVE-2026-59943mediumCVE-2026-59943 updated by NVD
- CVE-2026-59942mediumCVE-2026-59942 updated by NVD
- CVE-2026-59941mediumCVE-2026-59941 updated by NVD
- GHSA-pf2q-pxhf-hgmwmediumn8n: Path-Confinement Bypass in computer-use search_files Allows Reading Files Outside the Base Directory
- GHSA-hx4h-vr3m-45vhmediumn8n: Prototype Pollution via VM Expression Engine Sandbox Escape Leads to Denial of Service
- GHSA-xwx6-jjhv-84p8highn8n: Prototype Pollution via Dot-Notation Field Names Leads To Instance-Wide Denial of Service
- GHSA-xmc9-4f2h-jf9chighn8n: Edit Image Node Format Injection Allows Arbitrary File Write
- GHSA-cj9h-qx8g-pq2ghighn8n: Shared-Workflow Editor Can Exfiltrate Credentials via Inline Sub-Workflow JSON
- GHSA-6qc9-mqvw-jg7xhighn8n: Credential Authorization Bypass via Expression in HTTP Request Node `genericAuthType`
- GHSA-gv7g-jm28-cr3mhighn8n: Expression sandbox escape via arrow-function bodies enabling command execution
- GHSA-2x35-3fw4-9jr4highn8n: Send Email Node Arbitrary File Read and SSRF via Nodemailer Content-Object Type Confusion
- GHSA-rcv6-pvrj-4xcghighn8n: Authenticated code execution in the n8n Git node
- GHSA-vhf8-cg2h-cg3pmediumn8n: SSRF Protection Bypass via MCP Client Node
- GHSA-gf29-4f56-r2jfhighn8n: Git Node fetch/pull/pushTags Operations Bypass Sandbox Path Restriction
- GHSA-64xh-79j6-r5v8highn8n: Bypass "Allowed HTTP Request Domains" Credential Restriction in Multiple AI and LLM Nodes
- GHSA-8342-988q-86crhighn8n: Account Takeover via Unverified Email Claim in Token Exchange Embed Login
- CVE-2026-59921mediumCVE-2026-59921 updated by NVD
- CVE-2026-59920mediumCVE-2026-59920 updated by NVD
- CVE-2026-59919mediumCVE-2026-59919 updated by NVD
- CVE-2026-59901highCVE-2026-59901 updated by NVD
- CVE-2026-59900mediumCVE-2026-59900 updated by NVD
- CVE-2026-59899mediumCVE-2026-59899 updated by NVD
- CVE-2026-59898mediumCVE-2026-59898 updated by NVD
- CVE-2026-56822highCVE-2026-56822 updated by NVD
- CVE-2026-56821highCVE-2026-56821 updated by NVD
- CVE-2026-56722mediumCVE-2026-56722 updated by NVD
- CVE-2026-55555lowCVE-2026-55555 updated by NVD
- CVE-2026-55554lowCVE-2026-55554 updated by NVD
- GHSA-725q-c4vp-q4cghighDuplicate Advisory: Race Condition in Git Clone Node Allows Authenticated Users to Achieve Remote Code Executi
- GHSA-mhvh-gwhr-76pwmediumDuplicate Advisory: Google Service Account Private Key Exposed in JWT Header
- GHSA-vhcw-f978-xjjghighDuplicate Advisory: DOM-Based XSS via Unsandboxed iframe srcdoc in HTML Preview
- GHSA-w46p-w7w2-fr9ghighDuplicate Advisory: AI Agents Project Viewer Privilege Escalation via run_node_tool
- GHSA-m7jc-p4hf-xhwqhighDuplicate Advisory: Legacy Expression Evaluator Sanitizer Bypass Leads to Authenticated Code Execution
- GHSA-mwq7-vcmc-cm4qhighDuplicate Advisory: SSO Instance-Role Provisioning Allows Privilege Escalation to Instance Owner
- GHSA-h9fm-xcv2-qfw3mediumDuplicate Advisory: Unauthenticated Endpoint Allows Cancellation of Any User's Active Test Webhook
- GHSA-wq64-hcrf-8m56highDuplicate Advisory: n8n: Privilege Escalation and Code Execution via Full Public API Key Scope Assignment to T
- GHSA-h5xr-fqvj-253phighDuplicate Advisory: Stored DOM XSS via Resource Locator `cachedResultUrl`
- GHSA-4v35-78jc-648rmediumDuplicate Advisory: computer-use Shell Sandbox Not Enforced on Linux and Windows
- GHSA-88c4-pcqm-3r9pmediumDuplicate Advisory: GraphQL Node Bypasses "Allowed HTTP Request Domains" Restriction
- GHSA-fmvg-vhqq-r2mjmediumDuplicate Advisory: Custom Header Credential Values Leaked in Plaintext into LLM Node Execution Data
- GHSA-38fj-36m5-783cmediumDuplicate Advisory: Authenticated SSRF via Dynamic Node Parameters Endpoints Allows Internal Network Access
- GHSA-5vfw-jc4p-fj39mediumDuplicate Advisory: Member-Level Users Can Execute Other Users' MCP Server Trigger Workflows via Missing OAuth
- GHSA-f88m-g3jw-g9cjhighsharp inherited vulnerabilities in libvips: CVE-2026-33327, CVE-2026-33328, CVE-2026-35590, CVE-2026-35591
- GHSA-8r6m-32jq-jx6qhighfast-xml-parser: Repeated DOCTYPE declarations reset entity expansion limits
- GHSA-rwj8-pgh3-r573highGitPython: Environment-variable exfiltration via os.path.expandvars() on Repo.clone_from() URL
- GHSA-cj75-f6xr-r4g7mediumRails HTML Sanitizers: Possible XSS vulnerability with certain configurations
- GHSA-9mqv-5hh9-4cggmediumNode.js Adapter for Hono: Unauthenticated memory-leak DoS via aborted WebSocket handshake
- GHSA-hrxh-6v49-42gfhighgRPC-Go: xDS RBAC and HTTP/2 Vulnerabilities
- GHSA-5qhf-9phg-95m2lowLoofah `allowed_uri?` does not detect `javascript:` URIs split by numeric character references without semicol
- GHSA-9wjq-cp2p-hrgfmediumLoofah: SVG `href` attribute bypasses local-reference restriction
- GHSA-2rp8-mm9q-fp49mediumTypeORM: migration:generate template-literal code injection
- GHSA-r7wm-3cxj-wff9highjackson-core: Async parser maxNumberLength bypass via chunked digit accumulation (incomplete fix for GHSA-72hv
- CVE-2026-58429mediumGitea: Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints
- CVE-2026-59765mediumGitea: SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata
- CVE-2026-58511lowGitea: Webhook Authorization Header Returned in Plaintext via API
- CVE-2026-57897mediumGitea: Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs
- CVE-2026-58510mediumGitea: GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains st
- CVE-2026-58431mediumGitea: Public-only API token restriction is not enforced on team API routes
- CVE-2026-58427mediumGitea: Private org member list leaked via /members API endpoint — incomplete fix for PR #38145
- CVE-2026-58314highGitea: Two SSRF findings
- CVE-2026-58436highGitea: ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests
- CVE-2026-56657mediumGitea SSH Key Parser Denial of Service
- CVE-2026-58437highGitea: Repository Visibility Manipulation via Git Push Options
- CVE-2026-55987highGitea: OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens
- CVE-2026-58435mediumGitea LFS Deploy-Key Privilege Escalation
- CVE-2026-58420mediumGitea: Local File Inclusion via file:// URI in Migration Restore
- CVE-2026-55984lowGitea: Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service
- CVE-2026-55982mediumGitea: OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes
- CVE-2026-58434lowGitea: Private Repository Metadata Remains Accessible After Access Revocation
- CVE-2026-54481highGitea: Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override
- CVE-2026-58417mediumGitea: REST API exposes organization membership of private organizations to public
- CVE-2026-50105mediumGitea: RSS/Atom feed handlers bypass API-token scope & public-only confinement (incomplete fix of #37698)
- CVE-2026-58416mediumGitea: Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fo
- CVE-2026-42931mediumGitea: Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint
- CVE-2026-58445lowGitea: Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API
- CVE-2026-58444mediumGitea: Personal access token scope enforcement bypass on the repository home page (`GET /{owner}/{repo}`) disc
- CVE-2026-58443criticalGitea: Public-only repository tokens can update private PR head branches
- CVE-2026-58442mediumGitea: Repository migration SSRF via multi-answer DNS allow-list bypass
- CVE-2026-58441mediumGitea: SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL
- CVE-2026-58438lowGitea: Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private r
- GHSA-rjvx-x5h2-6px5mediumGitea: API Fork Endpoint Authorization Bypass Allows Organization Members to Bypass Repository Creation Restri
- CVE-2026-56654highGitea: Privilege Escalation via Access Token Scope Escalation in API
- CVE-2026-56755highGitea: Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Uploa
- CVE-2026-58507mediumGitea: Private Repository Existence Disclosure via go-get Meta Endpoint
- CVE-2026-57886mediumGitea: Cross-repository issue/comment attachment re-linking can expose private attachment content
- CVE-2026-23603lowGitea: Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claim
- CVE-2026-58425mediumGitea: OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violat
- CVE-2026-59763mediumGitea: Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads
- CVE-2026-56750criticalGitea Remember-Me Token Theft Not Invalidating Attacker Session
- CVE-2026-58432mediumGitea: draft release attachment disclosure via missing web authorization
- CVE-2026-58428mediumGitea: Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939)
- CVE-2026-56443mediumGitea: Token public-only scope bypassed on Limited-visibility owners (Repository + Package categories) — resid
- CVE-2026-58439highGitea: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag
- CVE-2026-59766mediumGitea CVE-2026-20800 sibling endpoints not covered: revoked user still reads private repo objects via `/api/v1
- CVE-2026-58440mediumGitea: Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time e
- GHSA-956x-8gvw-wg5vhighGitPython: command injection via unguarded Git options in `Repo.archive()`, `git.ls_remote()`, and arbitrary f
- GHSA-2f96-g7mh-g2hxhighGitPython: Command Injection via git long-option prefix abbreviation bypass of CVE-2026-42215 blocklist
- GHSA-v396-v7q4-x2qjhighGitPython unsafe clone option gate bypass through joined short options
- GHSA-2p49-hgcm-8545highSVGO removeScripts plugin leaves some executable scripts intact
- GHSA-c2j3-45gr-mqc4lowDOMPurify: `CUSTOM_ELEMENT_HANDLING` bypasses `afterSanitizeElements` for allowed custom elements.
- GHSA-mhm7-754m-9p8wmediumjackson-databind: `@JsonView` bypass for creator properties with `@JsonTypeInfo(include=As.EXTERNAL_PROPERTY)`
- GHSA-p63j-vcc4-9vmvcritical@vitest/browser: Browser Mode provider commands bypass the file-access permission gate
- CVE-2026-57894highGitea: Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git
- CVE-2026-61666highwebsocket-driver-ruby: Denial of service via malformed Host header
- GHSA-frvp-7c67-39w9mediumNode.js Adapter for Hono: Path traversal in `serve-static` on Windows via encoded backslash (`%5C`)
- GHSA-8whx-365g-h9vvlowLoofah `allowed_uri?` does not detect `javascript:` URIs split by named whitespace character references
- GHSA-8qqm-fp2q-v734highSkipper: Incomplete fix for CVE-2026-50197: an oversized body can bypass OPA deny-on-presence Rego policies
- GHSA-3j7v-fhjg-6rh2mediumDuplicate Advisory: n8n: External Secrets Accessible via Workflow Expressions Outside Credentials
- GHSA-q6mx-qvhp-fqmgmediumDuplicate Advisory: External Secrets Permission Bypass via Expression Parser Mismatch
- GHSA-2vww-6p9h-5g8jmediumDuplicate Advisory: Authenticated Users Can Exhaust Temporary Disk Storage via Data-Table File Uploads
- GHSA-2qp2-6frj-p9pqmediumDuplicate Advisory: MySQL v1 Node executeQuery Operation Allows SQL Injection via Unparameterized Expression I
- GHSA-gqcv-rfj6-r29gmediumDuplicate Advisory: Improper Authorization Allows Authenticated Users to Assign Workflows to Folders in Other
- CVE-2026-50029mediumjs-toml has silent type confusion via falsy-primitive duplicate-key bypass
- GHSA-75mw-h36v-2jv7mediumDosage Vulnerable to Stored Cross-Site Scripting (XSS) in HTML/RSS Output Handlers
- GHSA-wjv4-x9w8-wm3hlowNokogiri: Possible Use-After-Free when setting `Document#root=` to an invalid node type
- CVE-2026-57496criticalnetlicensing-mcp: REST Path Traversal Bypasses Token Redaction
- GHSA-7cx2-g3h9-382phighCrawl4AI: Arbitrary file write (symlink/TOCTOU) plus log and webhook-header injection in Docker server
- GHSA-g7r4-m6w7-qqqrlowesbuild allows arbitrary file read when running the development server on Windows
- GHSA-g53w-w6mj-hrppcriticalMCP Gateway: Authority-injection and JWT/session bypass via the unauthenticated router hair-pin "router-k
- GHSA-m7j5-r2p5-c39rmediumpicklescan vulnerable to arbitrary file create using logging.FileHandler
- GHSA-99pg-hqvx-r4gfcriticalFlowise has an Arbitrary File Read
- GHSA-36jr-mh4h-2g58highd3-color vulnerable to ReDoS
- CVE-2026-18363criticalCVE-2026-18363 updated by NVD
- CVE-2026-66723highCVE-2026-66723 updated by NVD
- CVE-2026-66724mediumCVE-2026-66724 updated by NVD
- CVE-2026-33385mediumCVE-2026-33385 updated by NVD
- CVE-2026-50641highCVE-2026-50641 updated by NVD
- CVE-2026-50642mediumCVE-2026-50642 updated by NVD
- CVE-2026-56390mediumCVE-2026-56390 updated by NVD
- CVE-2026-56389mediumCVE-2026-56389 updated by NVD
- CVE-2026-67178highCVE-2026-67178 updated by NVD
- CVE-2026-67174criticalCVE-2026-67174 updated by NVD
- CVE-2026-66921mediumCVE-2026-66921 updated by NVD
- CVE-2026-66920highCVE-2026-66920 updated by NVD
- CVE-2026-66919mediumCVE-2026-66919 updated by NVD
- CVE-2026-66918highCVE-2026-66918 updated by NVD
- CVE-2026-66913mediumCVE-2026-66913 updated by NVD
- CVE-2026-66825mediumCVE-2026-66825 updated by NVD
- CVE-2026-66824criticalCVE-2026-66824 updated by NVD
- CVE-2026-57916mediumCVE-2026-57916 updated by NVD
- CVE-2026-57917mediumCVE-2026-57917 updated by NVD
- CVE-2026-14856mediumCVE-2026-14856 updated by NVD
- CVE-2026-12990highCVE-2026-12990 updated by NVD
- CVE-2026-12989highCVE-2026-12989 updated by NVD
- CVE-2026-12495mediumCVE-2026-12495 updated by NVD
- CVE-2026-16554mediumCVE-2026-16554 updated by NVD
- CVE-2026-15243highCVE-2026-15243 updated by NVD
- CVE-2026-56392lowCVE-2026-56392 updated by NVD
- CVE-2026-56391mediumCVE-2026-56391 updated by NVD
- CVE-2026-53910lowCVE-2026-53910 updated by NVD
- CVE-2026-16270mediumCVE-2026-16270 updated by NVD
- CVE-2026-57311mediumCVE-2026-57311 updated by NVD
- CVE-2026-57310mediumCVE-2026-57310 updated by NVD
- CVE-2026-57309criticalCVE-2026-57309 updated by NVD
- CVE-2026-9058criticalCVE-2026-9058 updated by NVD
- CVE-2026-60472highCVE-2026-60472 updated by NVD
- CVE-2026-60489highCVE-2026-60489 updated by NVD
- CVE-2026-60490highCVE-2026-60490 updated by NVD
- CVE-2026-60491mediumCVE-2026-60491 updated by NVD
- CVE-2026-60492highCVE-2026-60492 updated by NVD
- CVE-2026-60493highCVE-2026-60493 updated by NVD
- CVE-2026-60494highCVE-2026-60494 updated by NVD
- CVE-2026-60495highCVE-2026-60495 updated by NVD
- CVE-2026-60496highCVE-2026-60496 updated by NVD
- CVE-2026-60497highCVE-2026-60497 updated by NVD
- CVE-2026-60498highCVE-2026-60498 updated by NVD
- CVE-2026-60499highCVE-2026-60499 updated by NVD
- CVE-2026-60501mediumCVE-2026-60501 updated by NVD
- CVE-2026-60502highCVE-2026-60502 updated by NVD
- CVE-2026-60503highCVE-2026-60503 updated by NVD
- CVE-2026-60519highCVE-2026-60519 updated by NVD
- CVE-2026-60520highCVE-2026-60520 updated by NVD
- CVE-2026-60521mediumCVE-2026-60521 updated by NVD
- CVE-2026-60522highCVE-2026-60522 updated by NVD
- CVE-2026-60523highCVE-2026-60523 updated by NVD
- CVE-2026-60524criticalCVE-2026-60524 updated by NVD
- CVE-2026-60525highCVE-2026-60525 updated by NVD
- CVE-2026-60526mediumCVE-2026-60526 updated by NVD
- CVE-2026-60527highCVE-2026-60527 updated by NVD
- CVE-2026-60528highCVE-2026-60528 updated by NVD
- CVE-2026-60529highCVE-2026-60529 updated by NVD
- CVE-2026-60530highCVE-2026-60530 updated by NVD
- CVE-2026-60531criticalCVE-2026-60531 updated by NVD
- CVE-2026-60532criticalCVE-2026-60532 updated by NVD
- CVE-2026-60533highCVE-2026-60533 updated by NVD
- CVE-2026-60534highCVE-2026-60534 updated by NVD
- CVE-2026-60535criticalCVE-2026-60535 updated by NVD
- CVE-2026-60536highCVE-2026-60536 updated by NVD
- CVE-2026-60537criticalCVE-2026-60537 updated by NVD
- CVE-2026-60538criticalCVE-2026-60538 updated by NVD
- CVE-2026-60539highCVE-2026-60539 updated by NVD
- CVE-2026-60540criticalCVE-2026-60540 updated by NVD
- CVE-2026-60541criticalCVE-2026-60541 updated by NVD
- CVE-2026-60542criticalCVE-2026-60542 updated by NVD
- CVE-2026-60543highCVE-2026-60543 updated by NVD
- CVE-2026-60544highCVE-2026-60544 updated by NVD
- CVE-2026-60545highCVE-2026-60545 updated by NVD
- CVE-2026-60546highCVE-2026-60546 updated by NVD
- CVE-2026-60547criticalCVE-2026-60547 updated by NVD
- CVE-2026-60548highCVE-2026-60548 updated by NVD
- CVE-2026-60549highCVE-2026-60549 updated by NVD
- CVE-2026-60550highCVE-2026-60550 updated by NVD
- CVE-2026-60551criticalCVE-2026-60551 updated by NVD
- CVE-2026-60552criticalCVE-2026-60552 updated by NVD
- CVE-2026-60553highCVE-2026-60553 updated by NVD
- CVE-2026-60554highCVE-2026-60554 updated by NVD
- CVE-2026-60555criticalCVE-2026-60555 updated by NVD
- CVE-2026-60556highCVE-2026-60556 updated by NVD
- CVE-2026-60557mediumCVE-2026-60557 updated by NVD
- CVE-2026-60558highCVE-2026-60558 updated by NVD
- CVE-2026-60559highCVE-2026-60559 updated by NVD
- CVE-2026-60560highCVE-2026-60560 updated by NVD
- CVE-2026-60561criticalCVE-2026-60561 updated by NVD
- CVE-2026-60562criticalCVE-2026-60562 updated by NVD
- CVE-2026-60563highCVE-2026-60563 updated by NVD
- CVE-2026-60564criticalCVE-2026-60564 updated by NVD
- CVE-2026-60565criticalCVE-2026-60565 updated by NVD
- CVE-2026-60566criticalCVE-2026-60566 updated by NVD
- CVE-2026-60567criticalCVE-2026-60567 updated by NVD
- CVE-2026-60568criticalCVE-2026-60568 updated by NVD
- CVE-2026-60569mediumCVE-2026-60569 updated by NVD
- CVE-2026-60570highCVE-2026-60570 updated by NVD
- CVE-2026-60571mediumCVE-2026-60571 updated by NVD
- CVE-2026-60572mediumCVE-2026-60572 updated by NVD
- CVE-2026-60573mediumCVE-2026-60573 updated by NVD
- CVE-2026-60574mediumCVE-2026-60574 updated by NVD
- CVE-2026-60575mediumCVE-2026-60575 updated by NVD
- CVE-2026-60576highCVE-2026-60576 updated by NVD
- CVE-2026-60577highCVE-2026-60577 updated by NVD
- CVE-2026-60578highCVE-2026-60578 updated by NVD
- CVE-2026-60579highCVE-2026-60579 updated by NVD
- CVE-2026-60580highCVE-2026-60580 updated by NVD
- CVE-2026-60581highCVE-2026-60581 updated by NVD
- CVE-2026-60582highCVE-2026-60582 updated by NVD
- CVE-2026-60583highCVE-2026-60583 updated by NVD
- CVE-2026-60584highCVE-2026-60584 updated by NVD
- CVE-2026-60585mediumCVE-2026-60585 updated by NVD
- CVE-2026-60586highCVE-2026-60586 updated by NVD
- CVE-2026-60587mediumCVE-2026-60587 updated by NVD
- CVE-2026-60588mediumCVE-2026-60588 updated by NVD
- CVE-2026-6059mediumCVE-2026-6059 updated by NVD
- CVE-2026-60593highCVE-2026-60593 updated by NVD
- CVE-2026-60594highCVE-2026-60594 updated by NVD
- CVE-2026-60595mediumCVE-2026-60595 updated by NVD
- CVE-2026-60596lowCVE-2026-60596 updated by NVD
- CVE-2026-60597highCVE-2026-60597 updated by NVD
- CVE-2026-60598highCVE-2026-60598 updated by NVD
- CVE-2026-60599highCVE-2026-60599 updated by NVD
- CVE-2026-60600highCVE-2026-60600 updated by NVD
- CVE-2026-60601mediumCVE-2026-60601 updated by NVD