Security advisories — page 8
- CVE-2026-63336mediumCVE-2026-63336 updated by NVD
- CVE-2026-73423mediumCVE-2026-73423 updated by NVD
- CVE-2026-9318mediumCVE-2026-9318 updated by NVD
- CVE-2026-54663mediumCVE-2026-54663 updated by NVD
- CVE-2026-64785mediumCVE-2026-64785 updated by NVD
- CVE-2026-72832mediumCVE-2026-72832 updated by NVD
- CVE-2026-73842criticalCVE-2026-73842 updated by NVD
- CVE-2026-54736highPhalcon: Non-constant-time HMAC verification in `Encryption\Crypt::decrypt` (timing side-channel)
- CVE-2026-70596mediumCVE-2026-70596 updated by NVD
- CVE-2026-62324mediumCVE-2026-62324 updated by NVD
- CVE-2026-73490mediumCVE-2026-73490 updated by NVD
- CVE-2026-3433mediumMattermost doesn't restrict role_updated websocket event broadcasts to members of the affected team or channel
- CVE-2026-72701mediumCVE-2026-72701 updated by NVD
- CVE-2026-61593highCVE-2026-61593 updated by NVD
- CVE-2026-55537highCVE-2026-55537 updated by NVD
- CVE-2026-71308highCVE-2026-71308 updated by NVD
- CVE-2026-58263highCVE-2026-58263 updated by NVD
- CVE-2026-53833highCVE-2026-53833 updated by NVD
- CVE-2026-10722lowCVE-2026-10722 updated by NVD
- CVE-2026-71322mediumCVE-2026-71322 updated by NVD
- CVE-2026-49756lowCVE-2026-49756 updated by NVD
- CVE-2026-65913mediumCVE-2026-65913 updated by NVD
- CVE-2026-58426criticalGitea Actions Artifacts V4 signed URL HMAC ambiguity allows cross-repository artifact read and cross-task uplo
- CVE-2026-41852lowCVE-2026-41852 updated by NVD
- CVE-2026-70595mediumCVE-2026-70595 updated by NVD
- CVE-2026-16729mediumCVE-2026-16729 updated by NVD
- CVE-2026-16728mediumCVE-2026-16728 updated by NVD
- CVE-2026-55478mediumSnipe-IT has missing object-level authorization in Kits API
- CVE-2026-69247highCVE-2026-69247 updated by NVD
- CVE-2026-54557mediummise HTTP backend uses raw version path for install symlink destination
- CVE-2026-54007highOpen WebUI: Cross-origin postMessage confirmation bypass via action:submit
- CVE-2026-54096highFile Browser: Improper Access Control Occurs via Pre-Created Public Share for a Non-existent Path
- CVE-2026-75911highCVE-2026-75911 updated by NVD
- CVE-2026-55697highpnpm: Repository-controlled configDependencies can select a pacquet native install engine
- CVE-2026-29113lowCVE-2026-29113 updated by NVD
- CVE-2026-41701mediumCVE-2026-41701 updated by NVD
- CVE-2026-63405mediumCVE-2026-63405 updated by NVD
- CVE-2026-63225mediumCVE-2026-63225 updated by NVD
- CVE-2026-41008mediumCVE-2026-41008 updated by NVD
- CVE-2026-41715mediumCVE-2026-41715 updated by NVD
- CVE-2026-82396mediumCVE-2026-82396 updated by NVD
- CVE-2026-70589mediumCVE-2026-70589 updated by NVD
- CVE-2026-73425lowCVE-2026-73425 updated by NVD
- CVE-2026-41838mediumCVE-2026-41838 updated by NVD
- CVE-2026-61591highCVE-2026-61591 updated by NVD
- CVE-2026-65900mediumCVE-2026-65900 updated by NVD
- CVE-2026-65912mediumCVE-2026-65912 updated by NVD
- CVE-2026-71438lowCVE-2026-71438 updated by NVD
- CVE-2026-59253mediumn8n: Improper Authorization Allows Authenticated Users to Assign Workflows to Folders in Other Projects
- CVE-2026-41847mediumCVE-2026-41847 updated by NVD
- CVE-2026-75526mediumCVE-2026-75526 updated by NVD
- CVE-2026-70666highCVE-2026-70666 updated by NVD
- CVE-2026-71850mediumCVE-2026-71850 updated by NVD
- CVE-2026-86038highCVE-2026-86038 updated by NVD
- CVE-2026-61453mediumGrav: XSS Blueprint Validation Bypass via Twig String Concatenation
- CVE-2026-46517highCVE-2026-46517 updated by NVD
- CVE-2026-71514lowCVE-2026-71514 updated by NVD
- CVE-2026-54262mediumWagtail: Pages translations can be created without page permissions when using simple_translation
- CVE-2026-54259mediumWagtail: Improper restriction handling on Documents and Images chosen endpoints
- CVE-2026-40181mediumCVE-2026-40181 updated by NVD
- CVE-2026-65602mediumCVE-2026-65602 updated by NVD
- CVE-2026-70602mediumCVE-2026-70602 updated by NVD
- CVE-2026-41845highCVE-2026-41845 updated by NVD
- CVE-2026-77063lowCVE-2026-77063 updated by NVD
- CVE-2026-84366highCVE-2026-84366 updated by NVD
- CVE-2026-70594mediumCVE-2026-70594 updated by NVD
- CVE-2026-11479lowCVE-2026-11479 updated by NVD
- CVE-2026-81868mediumCVE-2026-81868 updated by NVD
- CVE-2026-50526highCVE-2026-50526 updated by NVD
- CVE-2026-46345highCVE-2026-46345 updated by NVD
- CVE-2026-9793mediumCVE-2026-9793 updated by NVD
- CVE-2026-70606mediumCVE-2026-70606 updated by NVD
- CVE-2026-54353high@budibase/backend-core has potential SSRF DNS rebinding bypass in outbound fetch validation
- CVE-2026-61589mediumCVE-2026-61589 updated by NVD
- CVE-2026-71498mediumCVE-2026-71498 updated by NVD
- CVE-2026-49836mediumCVE-2026-49836 updated by NVD
- CVE-2026-46611mediumGlances: XML-RPC Server Missing Host Header Validation Enables DNS Rebinding Attack
- CVE-2026-77610mediumCVE-2026-77610 updated by NVD
- CVE-2026-77607mediumCVE-2026-77607 updated by NVD
- CVE-2026-77608mediumCVE-2026-77608 updated by NVD
- CVE-2026-77606mediumCVE-2026-77606 updated by NVD
- CVE-2026-65898mediumCVE-2026-65898 updated by NVD
- CVE-2026-65901mediumCVE-2026-65901 updated by NVD
- CVE-2026-28377highGrafana Tempo has Inadequate Encryption Strength
- CVE-2026-73231highCVE-2026-73231 updated by NVD
- CVE-2026-55824lowCVE-2026-55824 updated by NVD
- CVE-2026-73505highCVE-2026-73505 updated by NVD
- CVE-2026-81890mediumCVE-2026-81890 updated by NVD
- CVE-2026-55663mediumCVE-2026-55663 updated by NVD
- CVE-2026-15157mediumCVE-2026-15157 updated by NVD
- CVE-2026-55522highCVE-2026-55522 updated by NVD
- CVE-2026-6689mediumMattermost doesn't enforce PermissionInviteUser when setting AllowOpenInvite or AllowedDomains during team cre
- CVE-2026-55580highCVE-2026-55580 updated by NVD
- CVE-2026-63328mediumCVE-2026-63328 updated by NVD
- CVE-2026-54785mediumCVE-2026-54785 updated by NVD
- CVE-2026-54656highCVE-2026-54656 updated by NVD
- CVE-2026-71538highCVE-2026-71538 updated by NVD
- CVE-2026-81888mediumCVE-2026-81888 updated by NVD
- CVE-2026-54545highCVE-2026-54545 updated by NVD
- CVE-2026-69112mediumCVE-2026-69112 updated by NVD
- CVE-2026-72783mediumCVE-2026-72783 updated by NVD
- CVE-2026-40995mediumCVE-2026-40995 updated by NVD
- CVE-2026-77609mediumCVE-2026-77609 updated by NVD
- CVE-2026-54625mediumCVE-2026-54625 updated by NVD
- CVE-2026-67448mediumCVE-2026-67448 updated by NVD
- CVE-2026-52839lowCVE-2026-52839 updated by NVD
- CVE-2026-54574highCVE-2026-54574 updated by NVD
- CVE-2026-54655highCVE-2026-54655 updated by NVD
- CVE-2026-33244mediumCVE-2026-33244 updated by NVD
- CVE-2026-59208highn8n: Cross-Issuer Token Exchange Account Binding via Subject-Only Identity Resolution
- CVE-2026-55767mediumCVE-2026-55767 updated by NVD
- CVE-2026-55569mediumCVE-2026-55569 updated by NVD
- CVE-2026-70599mediumCVE-2026-70599 updated by NVD
- CVE-2026-54654highCVE-2026-54654 updated by NVD
- CVE-2026-54621highCVE-2026-54621 updated by NVD
- CVE-2026-88014mediumCVE-2026-88014 updated by NVD
- CVE-2026-53945mediumGhost: Server-side request forgery via DNS rebinding in external request handling
- CVE-2026-10721highCVE-2026-10721 updated by NVD
- CVE-2026-41846mediumCVE-2026-41846 updated by NVD
- CVE-2026-73974mediumCVE-2026-73974 updated by NVD
- CVE-2026-68518highCVE-2026-68518 updated by NVD
- CVE-2026-35163mediumCVE-2026-35163 updated by NVD
- CVE-2026-81192highCVE-2026-81192 updated by NVD
- CVE-2026-16732mediumCVE-2026-16732 updated by NVD
- CVE-2026-84310mediumCVE-2026-84310 updated by NVD
- CVE-2026-84311mediumCVE-2026-84311 updated by NVD
- CVE-2026-62982highCVE-2026-62982 updated by NVD
- CVE-2026-73846mediumCVE-2026-73846 updated by NVD
- CVE-2026-69245mediumCVE-2026-69245 updated by NVD
- CVE-2026-41694lowCVE-2026-41694 updated by NVD
- CVE-2026-70600lowCVE-2026-70600 updated by NVD
- CVE-2026-53606mediumsanitize-html has incomplete URI scheme validation in that allows javascript: URIs through action, formaction,
- CVE-2026-81727mediumCVE-2026-81727 updated by NVD
- CVE-2026-70667mediumCVE-2026-70667 updated by NVD
- CVE-2026-63220mediumCVE-2026-63220 updated by NVD
- CVE-2026-72744mediumCVE-2026-72744 updated by NVD
- CVE-2026-70611mediumCVE-2026-70611 updated by NVD
- CVE-2026-41844mediumCVE-2026-41844 updated by NVD
- CVE-2026-53948mediumGhost: File Upload Content-Type Spoofing
- CVE-2026-71325mediumCVE-2026-71325 updated by NVD
- CVE-2026-54639highStyle Dictionary - Prototype Pollution in convertTokenData utility function
- CVE-2026-54605highCVE-2026-54605 updated by NVD
- CVE-2026-41714mediumCVE-2026-41714 updated by NVD
- CVE-2026-76845mediumCVE-2026-76845 updated by NVD
- CVE-2026-16584highCVE-2026-16584 updated by NVD
- CVE-2026-59894mediumCVE-2026-59894 updated by NVD
- CVE-2026-53657highLima: An arbitrary user in a QEMU VM could gain the root privilege in the VM via the guest agent socket
- CVE-2026-71870mediumCVE-2026-71870 updated by NVD
- CVE-2026-68499mediumCVE-2026-68499 updated by NVD
- CVE-2026-63119mediumCVE-2026-63119 updated by NVD
- CVE-2026-52841lowEasy!Appointments: Authorization bypass in Google OAuth provider binding lets any backend user rebind a peer p
- CVE-2026-73506mediumCVE-2026-73506 updated by NVD
- CVE-2026-54672highCVE-2026-54672 updated by NVD
- CVE-2026-40996mediumCVE-2026-40996 updated by NVD
- CVE-2026-55532highCVE-2026-55532 updated by NVD
- CVE-2026-12570mediumCVE-2026-12570 updated by NVD
- CVE-2026-77407highCVE-2026-77407 updated by NVD
- CVE-2026-84309mediumCVE-2026-84309 updated by NVD
- CVE-2026-71852mediumCVE-2026-71852 updated by NVD
- CVE-2026-12480mediumKeras: HDF5 virtual datasets can disclose local files
- CVE-2026-53423mediummembrane_mp4_plugin has an unauthenticated denial-of-service via BEAM atom table exhaustion
- CVE-2026-59897mediumHono: API Gateway v1 adapter can drop a distinct repeated request header value during de-duplication
- CVE-2026-49356low@babel/core: Arbitrary File Read via sourceMappingURL Comment
- CVE-2026-84305mediumCVE-2026-84305 updated by NVD
- CVE-2026-68519highCVE-2026-68519 updated by NVD
- CVE-2026-55529mediumCVE-2026-55529 updated by NVD
- CVE-2026-40992mediumCVE-2026-40992 updated by NVD
- CVE-2026-41854mediumCVE-2026-41854 updated by NVD
- CVE-2026-53946mediumGhost: Mobiledoc image-size fetch SSRF
- CVE-2026-64847mediumCVE-2026-64847 updated by NVD
- CVE-2026-75857highCVE-2026-75857 updated by NVD
- CVE-2026-67550mediumCVE-2026-67550 updated by NVD
- CVE-2026-54727highCVE-2026-54727 updated by NVD
- CVE-2026-52902mediumCVE-2026-52902 updated by NVD
- CVE-2026-56370lowImageMagick has out-of-bounds access in ConnectedComponentsImage() via CLI-controlled connected-components:* a
- CVE-2026-78680highCVE-2026-78680 updated by NVD
- CVE-2026-55860mediumCVE-2026-55860 updated by NVD
- CVE-2026-10775lowCVE-2026-10775 updated by NVD
- CVE-2026-78675highCVE-2026-78675 updated by NVD
- CVE-2026-54522lowCVE-2026-54522 updated by NVD
- CVE-2026-55609highCVE-2026-55609 updated by NVD
- CVE-2026-13769mediumAWS CLI: Overly permissive File Permissions
- CVE-2026-55530mediumCVE-2026-55530 updated by NVD
- CVE-2026-63310criticalCVE-2026-63310 updated by NVD
- CVE-2026-50568lowFission: SanitizeFilePath lexical HasPrefix bypass permits sibling-directory escape
- CVE-2026-54289mediumhono: Lambda@Edge adapter keeps only the last value of a repeated request header, dropping the rest
- CVE-2026-52857mediumCVE-2026-52857 updated by NVD
- CVE-2026-49834mediumCVE-2026-49834 updated by NVD
- CVE-2026-44018mediumDocling: Unsafe Archive Extraction and XML Parsing in METS-GBS Backend
- CVE-2026-71429mediumCVE-2026-71429 updated by NVD
- CVE-2026-71430mediumCVE-2026-71430 updated by NVD
- CVE-2026-63349highCVE-2026-63349 updated by NVD
- CVE-2026-53766mediumchrome-devtools-mcp: validatePath() does not canonicalize symlinks before enforcing roots
- CVE-2026-54620lowCVE-2026-54620 updated by NVD
- CVE-2026-54619lowCVE-2026-54619 updated by NVD
- CVE-2026-49114mediumCVE-2026-49114 updated by NVD
- CVE-2026-72702criticalCVE-2026-72702 updated by NVD
- CVE-2026-55597mediumImageMagick: Heap Buffer Over-Write in JP2 encoder when due to incorrect handling of arguments
- CVE-2026-55510mediumImageMagick: Use-After-Free in crafted 8BIM when identifying an image
- CVE-2026-54288mediumhono: Body Limit Middleware can be bypassed on AWS Lambda by understating `Content-Length`
- CVE-2026-53832highCVE-2026-53832 updated by NVD
- CVE-2026-12259mediumCVE-2026-12259 updated by NVD
- CVE-2026-70603mediumCVE-2026-70603 updated by NVD
- CVE-2026-70598lowCVE-2026-70598 updated by NVD
- CVE-2026-55628mediumCVE-2026-55628 updated by NVD
- CVE-2026-77404highCVE-2026-77404 updated by NVD
- CVE-2026-41001mediumCVE-2026-41001 updated by NVD
- CVE-2026-54548lowCVE-2026-54548 updated by NVD
- CVE-2026-54787lowCVE-2026-54787 updated by NVD
- CVE-2026-55595mediumImageMagick: Infinite Loop in connected-components when providing invalid arguments
- CVE-2026-71417highCVE-2026-71417 updated by NVD
- CVE-2026-11481lowCVE-2026-11481 updated by NVD
- CVE-2026-71317mediumCVE-2026-71317 updated by NVD
- CVE-2026-70597mediumCVE-2026-70597 updated by NVD
- CVE-2026-84381highCVE-2026-84381 updated by NVD
- CVE-2026-53765mediumChrome DevTools for agents: daemon.pid write follows symlinks in /tmp fallback runtime directory
- CVE-2026-54050mediumCVE-2026-54050 updated by NVD
- CVE-2025-15603lowWithdrawn Advisory: Open WebUI JWT Key Handler
- CVE-2026-53966highCVE-2026-53966 updated by NVD
- CVE-2026-54049highSakai Conversations has a Stored XSS Issue
- CVE-2026-46380mediumCVE-2026-46380 updated by NVD
- GHSA-jgh3-fggc-mcpmhighObot: Server-Side Request Forgery via remote MCP server URL
- GHSA-pr6h-vr44-xq8jmediumObot: MCP Registry API readable without authentication
- GHSA-xwmw-prc4-v3crhighObot: OAuth Dynamic Client Registration Enables API Token Theft via Audience Confusion
- CVE-2026-63374criticalAnyIO: TLSStream IDNA 2003 host name encoding enables potential TLS certificate spoofing
- GHSA-39wr-7q6h-cf68highLMDeploy has an SSRF bypass
- GHSA-jr78-w6w5-m8f8highSemantic MediaWiki'a missing authorization in the smwtask API module allows unauthenticated access to admin-on
- GHSA-9rcc-pmj8-ffhrmediumSemantic MediaWiki's Special:FacetedSearch cstate hidden inputs enable reflected XSS (residual of CVE-2025-103
- GHSA-xjw9-38cr-6372highdjust: A template binding inherits a context safety grant it never earned (XSS)
- GHSA-9395-2g46-rj3fhighdjust: Six template-layer defects emit attacker-controlled markup unescaped (XSS)
- GHSA-5648-rgj9-v224high@zereight/mcp-gitlab has multiple safety-control bypasses: execute_graphql read-only + allow-list bypass, unau
- GHSA-rf68-8gjr-36q7lowNezha: OAuth2 redirect_uri Host header injection regression when dashboard_host is empty
- GHSA-2xmm-m4wv-3fjhlowOctober CMS: Incomplete Scheme Validation in Image Resizer
- CVE-2026-61534criticalCVE-2026-61534 updated by NVD
- CVE-2026-59973highCVE-2026-59973 updated by NVD
- CVE-2026-56825highCVE-2026-56825 updated by NVD
- CVE-2026-56830mediumCVE-2026-56830 updated by NVD
- CVE-2026-56829highCVE-2026-56829 updated by NVD
- CVE-2026-56828highShopper: privilege escalation via improper Livewire admin component authorization
- CVE-2026-56826mediumShopping privilege escalation through missing authorization in Settings components
- CVE-2026-56831mediumCVE-2026-56831 updated by NVD
- CVE-2026-56827highCVE-2026-56827 updated by NVD
- CVE-2026-59971criticalCVE-2026-59971 updated by NVD
- CVE-2026-59960highCVE-2026-59960 updated by NVD
- GHSA-m3wp-48jr-vr4ghighmistral.rs: Unbounded Remote Media Fetch and Video Frame Expansion DoS
- GHSA-wfgq-w7cq-qj7jhighmistral.rs Media Loader: Unauthenticated SSRF and arbitrary local file read via image_url
- CVE-2026-55416highCVE-2026-55416 updated by NVD
- GHSA-x7m8-jrm8-hpvxhigh@eigenpal/docx-editor-react: CSS injection and print-time XSS via unescaped embedded font-family name
- CVE-2026-59185highIdentrail Cross-tenant IDOR: Client-supplied GitHub App installation_id is bound to the caller's workspace wit
- CVE-2026-59179high@openhop/server: Path Traversal in Flow ID File Operations
- CVE-2026-59177highESPHome Device Builder Dashboard: Unauthenticated dashboard access via the HA add-on ingress site bound to all
- CVE-2026-59176highfunctype-mcp-server: MCP `set_functype_version` Package Alias RCE via Unsanitized pnpm install + Dynamic Impor
- CVE-2026-59172highJoker linter executed project-local .jokerd/linter.* files during linting
- GHSA-hxjg-93wc-h8p8highKomari: Management Interface CSRF
- CVE-2026-59160highCVE-2026-59160 updated by NVD
- CVE-2026-59158highNuxt Ollama: Public Runtime Config Exposes Ollama API Key to Browser Clients
- CVE-2026-59157mediumCVE-2026-59157 updated by NVD
- CVE-2026-55864highCVE-2026-55864 updated by NVD
- CVE-2026-55073mediumCVE-2026-55073 updated by NVD
- CVE-2026-54529mediumCVE-2026-54529 updated by NVD
- CVE-2026-53495mediumCVE-2026-53495 updated by NVD
- CVE-2026-50024mediumCVE-2026-50024 updated by NVD
- CVE-2026-44282mediumCVE-2026-44282 updated by NVD
- CVE-2025-58363mediumLF Edge eKuiper: Arbitrary File and Directory Deletion via Path Traversal in Plugin Installation Endpoint
- CVE-2025-24979mediumLF Edge eKuiper: SSRF in External Service
- CVE-2025-24978lowLF Edge eKuiper: Self-XSS in External Service Creation
- CVE-2025-24890mediumCVE-2025-24890 updated by NVD
- GHSA-wmmp-3585-3rmpmediumNodemailer: IDN/Punycode domain allow-list bypass leads to email delivery to an attacker-controlled domain
- GHSA-2x7j-588g-ccc2highNodemailer: Quadratic (O(n²)) time complexity in addressparser allows remote denial of service via a crafted a
- GHSA-cc9r-2j5m-2m83mediumNodemailer: Recipient-domain validation bypass via RFC 5322 comment mis-parsing leads to email delivery to an
- GHSA-2q42-4q24-7rgvhighOpenAPI3 version value escapes `emitterOutputDir` and overwrites YAML/JSON outside the output tree
- GHSA-26w7-cxv4-gfx2criticalAstro: Remote code execution through AVIF image optimization
- GHSA-rgj7-g3m4-5g8chighsharp: Vulnerabilities in libheif: GHSA-g89c-p67h-r497 and GHSA-2jg2-4ch7-h545
- GHSA-j95f-988m-3j2fhighTiptap: Quadratic ReDoS in block and inline Markdown attribute parsing
- CVE-2026-84445highCVE-2026-84445 updated by NVD
- GHSA-2xp9-vwfh-vxw4criticalNext.js: Unauthenticated Remote Code Execution in Image Optimization API when AVIF files are used
- GHSA-8m3c-c648-2xjjmediumNodemailer: resolveContent() on a MailMessage bypasses disableFileAccess/disableUrlAccess when called with the
- GHSA-4qhr-qf46-fcrxhighDuplicate Advisory: Microsoft Security Advisory CVE-2026-71328 – .NET and Visual Studio Remote Code Execution
- GHSA-q72m-f2r4-w4cwhighDuplicate Advisory: Microsoft Security Advisory CVE-2026-69522 – .NET and Visual Studio Remote Code Execution
- GHSA-mqvm-gmc4-6rv2highDuplicate Advisory: Microsoft Security Advisory CVE-2026-69439 – .NET and Visual Studio Elevation of Privilege
- GHSA-v3f6-m9j2-437pmediumDuplicate Advisory: Microsoft Security Advisory CVE-2026-69304 – ASP.NET Core Denial of Service Vulnerability
- GHSA-57v5-wqx3-cgj4mediumSiYuan: Database view structure (all view names, layout types and per-field visibility) is returned to anonymo
- GHSA-7q9c-hpx7-9cwmhighTypeSpec: Unauthenticated Remote Shutdown of Spector Mock Server via POST /.admin/stop
- GHSA-6hxq-p678-4hr2lowSimpleWebAuthn: Registration verification does not sufficiently ensure that attestation certificates chain to
- GHSA-w8wf-3qvj-6xqfhighOpenClaw Feishu permission tools could ignore per-account disablement
- GHSA-2q7j-2vhx-56g8highOpenClaw Feishu tools could ignore per-account disablement
- GHSA-gw25-m53r-qh88mediumSiYuan: path traversal via /export/temp/ short-circuit branch (incomplete fix for the export-disclosure harden
- GHSA-99rq-75j6-5j9fhighSiYuan: Stored and reflected XSS in SiYuan through an SVG sanitizer bypass
- GHSA-cp6q-959q-f8rhmediumTiptap: mergeAttributes() turns an own __proto__ key into inherited executable DOM attributes
- CVE-2026-12876mediumNLTK: Uncontrolled resource consumption in RecursiveDescentParser via ambiguous or left-recursive grammars
- GHSA-cvhv-g4rq-3hmwlowImageMagick: Memory Leak when providing invalid options to the cli
- GHSA-p498-v437-472gmediumhumanfs: Recursive copy follows symlinked files and copies data from outside the source tree
- GHSA-8rr7-cvq3-gmfhhighleague/commonmark: Denial of service via distinctly-named attributes in the Attributes extension
- GHSA-jjv6-8j6v-6j52highleague/commonmark: Denial of service in the SmartPunct and Attributes extensions
- GHSA-f8fg-pg57-v4j8highleague/commonmark XSS: `on*` event-handler filter in `AttributesExtension` bypassed with a U+000C form feed
- GHSA-j8pm-gj4c-rq4xhighleague/commonmark: Denial of service via crafted code fences, reference links, and emphasis delimiters
- GHSA-8423-8fgw-73vqmediumtornado: multipart split() creates huge temp list before max_parts check -> memory amplification DoS (httpu
- GHSA-wwv5-g3v4-889xlowTornado: Incomplete fix for CVE-2026-35536: cookie attribute injection re-opened via the legacy case-insensiti
- GHSA-vx52-2968-3vc6highpnpm: Environment secrets exfiltrated via env-placeholder expansion in proxy settings read from an untrusted p
- GHSA-2rx9-3g3h-c2jvhighpnpm: pacquet trust-lockfile install can create dependency symlinks outside the project
- GHSA-gqvg-gmmx-x4hmhighMLFLOW_ALLOW_PICKLE_DESERIALIZATION=False safety control bypassed by mlflow.statsmodels flavor — RCE via craft
- GHSA-3f6p-5ww8-9rcrhighMySQL2: Auth Plugin Downgrade to mysql_clear_password Leaks Plaintext Credentials
- GHSA-rgwj-5xj2-c3m3mediumMySQL2: Unbounded zlib inflate in compressed MySQL protocol handler allows decompression-bomb DoS
- GHSA-vf76-f5cp-9846highDuplicate Advisory: ReDoS in nltk.tgrep via unvalidated user-supplied regular expressions
- GHSA-h3hj-cmcx-xc66highDuplicate Advisory: Nodemailer: Message-level raw option bypasses disableFileAccess/disableUrlAccess, enabling
- GHSA-73p9-6hrp-8qhrmediumAIIR verification and policy gates could report success without enforcing the control (fail-open)
- GHSA-2vh6-hw4j-32wwmediumgix-packetline: reachable panic on empty side-band packet (pre-auth network DoS)
- GHSA-3m7f-6hxv-6796mediumDuplicate Advisory: Pl196xCorpusReader has quadratic ReDoS on malformed TEI blocks
- GHSA-4xw3-jf9x-x7mfmediumDuplicate Advisory: Downloader.download follows hardlinks and overwrites outside-root files
- GHSA-pf76-q698-37v8mediumDuplicate Advisory: Uncontrolled recursion in nltk.featstruct.FeatStructReader causes unhandled RecursionError
- GHSA-hqj7-phwp-c3fphighDuplicate Advisory: Model-artifact APIs bypass pathsec and touch files outside allowed roots
- GHSA-8x48-8g7j-rqxphighDuplicate Advisory: Quadratic-time DoS in PorterStemmer via long runs of 'y'
- GHSA-hqv3-xm29-p9hqmediumDuplicate Advisory: Quadratic CPU Exhaustion in `XMLCorpusView._read_xml_fragment()`
- GHSA-mf7q-r4rv-jv94highCrossplane's TOCTOU between cosign verification and image fetch in xpkg.CachedClient allows tag-based package
- GHSA-2rrw-hpqm-36pvhighDuplicate Advisory: ReDoS in nltk.text.Text.findall() via unvalidated user-supplied regular expressions
- CVE-2026-44701lowOpenSTAManager has HTML Injection in modules/utenti/edit.php
- GHSA-7w8c-qgxg-m7jxhighLibreNMS — Stored XSS via SNMP/Syslog Data in Legacy Templates
- GHSA-x287-5c68-36wpmediumOpenWISP IPAM has broken object-level authorization: ExportSubnetView lets a member of one organization export
- GHSA-93qj-5q5v-3c2hcriticalTrojanized pantheon-agents 0.6.1 and 0.6.2 on PyPI ship a credential stealer (supply-chain account compromise)
- GHSA-xqqh-3w52-q8p7mediumDuplicate Advisory: Nokogiri does not check the return value from xmlC14NExecute
- GHSA-rcw8-9qrw-27m2highDuplicate Advisory: NLTK: Corpus Reader Sandbox Bypass
- GHSA-rh9x-7xjc-vwx2mediumDuplicate Advisory: Nokogiri XSLT transform has a memory leak
- GHSA-w5q8-6jpp-4246highDuplicate Advisory: Corpus readers follow symlinks outside trusted roots despite pathsec enforcement
- GHSA-3h2g-j4wp-7qqqcriticalDuplicate Advisory: JVM argument injection bypass via per-call options in the NLTK Stanford wrappers (incomple
- GHSA-5jhf-fpp7-v2pvhighDuplicate Advisory: Nokogiri CSS selector tokenizer has regular expression backtracking
- GHSA-vwf3-4xxj-qg6hhighmcp-contextforge-gateway has Server-Side Template Injection (SSTI) leading to Remote Code Execution in `Prompt
- GHSA-pg62-f8g4-4wqhhighphpMyFAQ privilege escalation: GroupController::updatePermissions lets a GROUP_EDIT admin grant rights they do
- GHSA-mf8r-wm2w-f8c5mediumphpMyFAQ public FAQ APIs expose inactive FAQ content
- GHSA-88g4-74f3-63x9mediumphpMyFAQ has Potential Authenticated Path Traversal in PDF Export
- GHSA-8qx3-8gm5-9cj2highpickem vulnerable to terminal escape-sequence injection via unsanitized item text
- GHSA-8cp3-qxj6-px34highutcp-http has an OAuth2 `tokenUrl` Trust Boundary Bypass in OpenAPI Conversion
- GHSA-9qhg-99ww-9mqchighutcp-http SSRF: HTTP tool invocation follows redirects without re-validating the target
- GHSA-vp9c-2pjm-8925criticalDuplicate Advisory: Allowlisted pickle loaders still permit code execution in current source
- GHSA-jx89-3qg8-p2mrhighDuplicate Advisory: Entity-expansion DoS (billion laughs) via remaining raw ElementTree parses (CWE-776)
- GHSA-89ff-m8wv-p99rhighDuplicate Advisory: GitPython: Incomplete unsafe_git_revision_options denylist omits --contents/-S, enabling a
- GHSA-6rj2-96f5-chj9highDuplicate Advisory: GitPython: TagReference.create positional reference bypasses kwargs-only --file guard, ena
- GHSA-crp9-r7rq-c8cghighDuplicate Advisory: pathsec SSRF protection can be bypassed when a proxy is configured
- GHSA-gx65-c5hj-vpv5criticalDuplicate Advisory: [CWE-502] Unsafe Pickle Deserialization in TransitionParser Allows Remote Code Execution
- GHSA-54xp-3ww7-6wjghighDuplicate Advisory: Uncontrolled search path when invoking the Graphviz 'dot' binary (CWE-426/CWE-427)
- GHSA-9557-234j-7rv9criticalDuplicate Advisory: Dormant multi-line git-config values are corrupted into live injected directives (e.g. cor
- GHSA-7r39-6q8m-qw68highDuplicate Advisory: clone_from()/clone() omit --separate-git-dir from unsafe_git_clone_options, enabling arbit
- GHSA-8vp7-8q4w-vv7mhighDuplicate Advisory: Grav: UserInterface offsetget/offsetexists allow-listed in Twig sandbox let editor-authore
- GHSA-crmc-f4m7-33fjhighDuplicate Advisory: Arbitrary local file content disclosure via [include] directive in untrusted .gitmodules (
- GHSA-crrc-vpp2-f5x7highDuplicate Advisory: Grav: config_denied_paths default list omits `system`, exposing real secrets (e.g. system.
- GHSA-qh7h-6c7g-x8m6criticalDuplicate Advisory: Grav: Origin validation bypass in Uri::referrer() and Pages::referrerRoute() via unanchore
- GHSA-896w-cw95-xq7whighDuplicate Advisory: Grav: Path Traversal in MediaUploadTrait::deleteFile() Allows Arbitrary File Deletion
- GHSA-px9v-979x-qmh9mediumDuplicate Advisory: Grav: Non constant time nonce comparison in Utils::verifyNonce() used for CSRF protection
- GHSA-rj4c-4q9x-543xhighDuplicate Advisory: Grav: media_directory() Twig function allows filesystem path traversal and file content di
- GHSA-mw85-cjh9-8hp7highDuplicate Advisory: Grav: The system, site, and theme Twig variables bypass the content sandbox entirely and a
- GHSA-fx4f-mhw4-qm7jmediumvibeio-http has a DoS vulnerability in HTTP/1.x chunked encoding parser triggered by maliciously crafted chunk
- GHSA-w8j7-39hp-8x59mediumCloudreve's remote download file paths can escape the selected destination directory
- GHSA-vx2m-jpxr-xv7wmediumCloudreve has Broken Access Control - Revoked Share Access Still Allows Signed File URL Generation via Cached
- GHSA-w67g-5rqw-f597mediumGorilla WebSocket Uses Cryptographically Weak PRNG for WebSocket Mask Key
- GHSA-4ph6-mjv7-3fq6lownetfoil vulnerable to improper handling of untrusted DoH response data
- GHSA-3gjw-f78c-vvpwmediumtokio-postgres: Panic on a `DataRow` with fewer fields than columns allows denial of service
- GHSA-rgqc-3x5p-6gwgmediumpostgres-protocol: Panic decoding a malformed `hstore` value allows denial of service
- GHSA-5x78-73v4-xg6whighpostgres-protocol: Unbounded SCRAM iteration count allows a malicious server to cause CPU-exhaustion denial of
- CVE-2026-53710criticalCVE-2026-53710 updated by NVD
- GHSA-892m-gcq8-2468highDuplicate Advisory: Uncontrolled recursion DoS in JustHTML() via deeply nested HTML
- GHSA-8h9m-22mv-qv5rhighDuplicate Advisory: Symlink escape in CorpusReader allows arbitrary local file read outside the corpus root
- GHSA-8w48-h75v-cxpvhighDuplicate Advisory: Security Report: StreamBackedCorpusView Bypasses pathsec.ENFORCE - Arbitrary Local File Re
- GHSA-cv2g-m8rr-888chighDuplicate Advisory: Natural Language Toolkit (NLTK) has unbounded recursion in JSONTaggedDecoder.decode_obj()
- GHSA-qq3h-cgj8-w3fxhighDuplicate Advisory: Symlink-based sandbox bypass in FramenetCorpusReader (bypasses the fix for CVE-2026-54292)
- GHSA-qp76-pq9f-gr9mhighDuplicate Advisory: Stable FrameNet and NKJP readers parse outside-root XML in 3.9.4
- GHSA-qg9p-xrhj-435mmediumDuplicate Advisory: nltk: SSRF Fail-Open in validate_network_url() via DNS Resolution Failure
- GHSA-79ph-w9m5-4v5mhighDuplicate Advisory: FileSystemPathPointer.open() sandbox check is dead code — arbitrary file read via file://
- GHSA-8vh5-mgjj-w6hghighDuplicate Advisory: [CWE-1188] Default ENFORCE=False Disables All pathsec Security Controls
- GHSA-343m-9fqq-97c7mediumDuplicate Advisory: NLTK: Symlink-based arbitrary file read in IPIPANCorpusReader, bypasses nltk.pathsec entir
- GHSA-8hgv-xc77-jmcrmediumGrav: Page editors can inject arbitrary script into rendered pages via the Twig sandbox's assets.addJs/addCss
- GHSA-486p-g8x4-77mgmediumDuplicate Advisory: ONNX: TOCTOU arbitrary file read/write in save_external_dat
- CVE-2026-55451highCVE-2026-55451 updated by NVD
- GHSA-jm5p-837g-rv8gmediumWagtail: Improper restriction handling on Page translation API endpoint
- GHSA-x5cx-w6p2-mxf2mediumWagtail: Improper permission handling when copying snippets
- GHSA-c2xx-cjmh-9q8fmediumWagtail: Improper restriction handling on descendant collections in Documents and Images API
- GHSA-92hv-j533-69wclowWagtail: Identification of documents by SHA1 hash
- GHSA-hq84-x37p-j6q5mediumWinter: Reflected XSS through the search query parameter in the backend Table widget
- GHSA-p2ch-c2c3-4xm5mediumWinter: CSRF through AJAX handler names reachable as backend page actions
- GHSA-5cwr-5jxg-pcf6mediumWinter: Stored XSS through cached Brand Settings and Editor Settings custom styles
- GHSA-fm29-4mq3-phg6highWinter: ImportExportController AJAX handlers bypass granular import/export permission gate
- GHSA-mpmw-f6h6-3g26mediumWinter: My Account preview exposes another backend user's profile by record ID
- GHSA-7mpf-4465-7fc2lowWinter: Stored XSS through Backend List widget image columns
- GHSA-rxhg-vcww-2mpwlowFleet: ORDER BY column injection on activity list endpoints
- GHSA-q9c5-pp7m-fm2gmediumFleet: Unauthenticated download of in-house iOS app binaries via predictable URLs
- GHSA-8cfw-pcwh-v63whighWinter: Authenticated Twig sandbox escape in CMS SecurityPolicy (bypass of CVE-2024-54149)
- GHSA-2223-f22x-24cqmediumWinter: Local File Inclusion through =include directives in JavaScript asset compilation
- CVE-2026-63202highnetty-incubator-codec-ohttp BinaryHttpParser: Unauthenticated CPU-exhaustion DoS via infinite loop in field-se
- CVE-2026-63179mediumCVE-2026-63179 updated by NVD
- CVE-2026-61827highnetty-incubator-codec-ohttp: BinaryHttpParser should enforce limits for variable lengths fields
- CVE-2026-63124highnetty-incubator-codec-ohttp: Binary HTTP parser infinite loop on known-length field section boundary
- CVE-2026-61799mediumnetty-incubator-codec-ohttp: Binary HTTP parser unchecked varint length overflow causes decoder crash
- CVE-2026-61798highnetty-incubator-codec-ohttp: BoringSSL HPKE private key bytes exposed through toString() and exception message
- CVE-2026-57570mediumCVE-2026-57570 updated by NVD
- CVE-2026-55468mediumCVE-2026-55468 updated by NVD
- GHSA-ghvf-qf6h-g8x5highNocoBase: Arbitrary File Write chained with Local file Inclusion leads to Remote code execution
- CVE-2026-54256mediumCVE-2026-54256 updated by NVD
- CVE-2026-54251highCVE-2026-54251 updated by NVD
- CVE-2026-54182highCVE-2026-54182 updated by NVD
- CVE-2026-54181mediumCVE-2026-54181 updated by NVD
- CVE-2026-54180highCVE-2026-54180 updated by NVD
- CVE-2026-54179mediumCVE-2026-54179 updated by NVD
- CVE-2026-54178highCVE-2026-54178 updated by NVD
- CVE-2026-54177mediumCVE-2026-54177 updated by NVD
- CVE-2026-54176mediumCVE-2026-54176 updated by NVD
- CVE-2026-54175highCVE-2026-54175 updated by NVD
- CVE-2026-54168mediumCVE-2026-54168 updated by NVD
- CVE-2026-54167highCVE-2026-54167 updated by NVD
- GHSA-22w5-2fxg-vrwxlowOpenTofu has high CPU usage when using K8S remote state backend or when parsing specifically crafted TLS certi
- CVE-2026-54162mediumEmber has unneutralized terminal escape/control sequences from Caddy logs injected into the operator's TUI
- CVE-2026-54156highCVE-2026-54156 updated by NVD
- CVE-2026-54155highCVE-2026-54155 updated by NVD
- CVE-2026-54150mediumCVE-2026-54150 updated by NVD
- GHSA-h58c-xccx-75m3lowCoder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings
- GHSA-8fxq-53rx-ph5flowCoder: Login endpoint user enumeration via timing-defense placeholder in password comparison
- GHSA-mc9m-6fm9-pghcmediumZoo Design Studio: Memory-corruption in memory handling of lib-kcl
- GHSA-jgvr-6x5w-hx5wmediumZoo Design Studio: Recursive KCL parsing is vulnerable to denial-of-service
- GHSA-5p3m-vhh6-9236mediumstigmem-node has blind SSRF via unvalidated webhook subscription delivery_address
- CVE-2026-55253highCVE-2026-55253 updated by NVD
- CVE-2026-55244mediumCVE-2026-55244 updated by NVD
- GHSA-9w56-46f6-3qhxmediumasteval Sandbox Escape: arbitrary native memory read/write via numpy ctypes in default asteval Interpreter
- CVE-2026-55149highCVE-2026-55149 updated by NVD
- CVE-2026-45404mediumCVE-2026-45404 updated by NVD
- CVE-2026-32637mediumCVE-2026-32637 updated by NVD
- GHSA-hjwh-xvfw-qrwjmediumSearXNG Basic Authentication Credentials Exposed Through MCP Logs and JSON-RPC Error Responses
- CVE-2024-45747highGeoServer has a Server-Side Template Injection (SSTI) vulnerability in processing FreeMarker templates
- CVE-2026-54689mediumCVE-2026-54689 updated by NVD
- CVE-2026-54688mediumCVE-2026-54688 updated by NVD
- GHSA-p77j-g7h5-r2vwhighGeoLens's authorization and cache-scope flaws disclose private dataset data and metadata to unauthorized users
- CVE-2026-53964highDocument Merge Service vulnerable to RCE via SSTI (xlsx tempaltes)
- CVE-2026-53957highCVE-2026-53957 updated by NVD
- CVE-2026-53941mediumCVE-2026-53941 updated by NVD
- GHSA-qwgh-2vcv-g2f7mediumblock_buffer: panic corrupts inline buffer position
- GHSA-rr55-jp92-8wp2highclaude-faf-mcp has an arbitrary local file read/write via unconfined `path` argument in FAF tools
- GHSA-j4r7-8ph4-43g3highfaf-mcp has an arbitrary local file read/write via unconfined `path` argument in FAF tools
- GHSA-cc2g-gq8c-r332highgrok-faf-mcp has an arbitrary local file read via unconfined `path` argument in FAF tools
- CVE-2026-55236mediumCVE-2026-55236 updated by NVD
- CVE-2026-55235mediumCVE-2026-55235 updated by NVD
- GHSA-wv46-xpj8-pw53highDuplicate Advisory: GitPython: Unsafe git option guard bypass via split_single_char_options=False short-option
- GHSA-7jx3-jqcp-hhgchighDuplicate Advisory: GitPython: Unguarded git read-tree option forwarding in IndexFile.from_tree/reset/merge_tr
- GHSA-w672-239g-c3grhighDuplicate Advisory: GitPython: Arbitrary file read via --pathspec-from-file in IndexFile.remove() and Head.che
- GHSA-298h-jpq4-m665highDuplicate Advisory: GitPython: Unguarded git option forwarding in Repo.init enables arbitrary command executio
- GHSA-3vrx-526r-64rmhighDuplicate Advisory: GitPython: Arbitrary Git Repository Creation Outside the Working Tree via Unvalidated .git
- GHSA-7gww-x7fh-jf9jhighLibreNMS: SSRF-driven stored XSS via Oxidized API response fields in device showconfig page
- GHSA-7cj5-v4pp-v632mediumLibreNMS: Stored XSS via graph_descr admin config settings echoed without escaping to all authenticated users
- GHSA-jf24-8g2h-2wg7mediumLibreNMS Vulnerable to Remote Code Execution via AboutController
- CVE-2026-54723mediumCVE-2026-54723 updated by NVD
- CVE-2026-55224highMineAdmin Vulnerable to Path Traversal via Unsanitized identifier in Plugin Install/Uninstall
- GHSA-wg9g-w2j2-8pgrhighMONAI: Unsafe deserialization in NumpyReader allows arbitrary code execution via malicious .npy files
- GHSA-rghg-q7wp-9767highMONAI vulnerable to OS command injection
- GHSA-qxq5-qhx6-94qwhighIncomplete Fix in MONAI: algo_from_pickle() pickle.loads() RCE still present in v1.5.2 despite GHSA-89gg-p5r5-
- GHSA-vjf8-9fx6-mv6xmediumTriton VM Soundness Vulnerability due to Missing Constraint
- CVE-2026-55211criticalCVE-2026-55211 updated by NVD
- CVE-2026-55209criticalCVE-2026-55209 updated by NVD
- CVE-2026-55107criticalkobako Sandbox Escape: guest eval reaches host RCE via method_missing → public_send (any bound Service)
- GHSA-c7hr-448w-65pxhighMeshCentral has unsanitized data fields
- CVE-2026-55178highCVE-2026-55178 updated by NVD
- CVE-2026-55182highCVE-2026-55182 updated by NVD
- GHSA-2mf3-mr2r-r4vfhigh@rhinostone/swig: arbitrary local file read via include/extends path traversal
- GHSA-993v-76jg-67xrmediumDuplicate Advisory: Grav: Single invalid UTF-8 byte disables every rule in Security::detectXss(), bypassing th
- GHSA-m97h-2qj3-5773criticalDuplicate Advisory: Grav: Missing admin.super guard on core group blueprint access field allows admin.users op
- GHSA-q8cg-5m48-5c25mediumDuplicate Advisory: Grav: Stored XSS via Markdown audio/video media URL
- GHSA-fwwx-3362-3947criticalDuplicate Advisory: Grav: Blueprint dynamic-data bare-function branch is denylist-gated and omits error_log, g
- GHSA-9pr6-8r9w-wvmjcriticalDuplicate Advisory: Grav: detectXss() misses an event-handler attribute after an unpaired quote in an unquoted
- GHSA-2rhw-8953-48q3highDuplicate Advisory: Grav: Unauthenticated Path Traversal via Missing Directory-Boundary Check in `plugin-asset
- CVE-2026-54148highCVE-2026-54148 updated by NVD
- CVE-2026-54147mediumCVE-2026-54147 updated by NVD
- GHSA-mpwr-8vm7-h73fmediumpackage pkcs12: Authentication bypass in Decode functions
- CVE-2026-53752highCVE-2026-53752 updated by NVD
- CVE-2026-53659highCVE-2026-53659 updated by NVD
- GHSA-j659-8xh6-5pq5highatomic-agents-stack: Parallel helper/delegate batch reserves $0 for models absent from the pricing table, bypa
- GHSA-xhcr-cqfr-m3hvhighatomic-agents-stack: HTTP MCP catalog accepts cleartext http and spawns catalog-supplied commands (MITM to RCE
- GHSA-fhgh-wq4q-r37xhighuniget CLI: Metadata signature verification only runs when UNIGET_IGNORE_METADATA_SIGNATURE is set
- CVE-2026-55090mediumCVE-2026-55090 updated by NVD
- GHSA-92hr-gmr6-h8cpmediumEtherpad addressed weak token RNG, login timing, plugin path handling, API request handling
- CVE-2026-55062highCVE-2026-55062 updated by NVD
- CVE-2026-55061lowCVE-2026-55061 updated by NVD
- GHSA-v836-6xw4-9cx3highvm2 has Memory Exhaustion DoS via bufferAllocLimit Bypass
- GHSA-m5w8-4gq2-6f8xcriticalvm2: NodeVM `builtin: ['*']` exposes `os` and `dns` — process-wide observability reads AND writes that hijack
- CVE-2026-45099mediumCVE-2026-45099 updated by NVD
- CVE-2026-53728highCVE-2026-53728 updated by NVD
- CVE-2026-55158criticalCVE-2026-55158 updated by NVD
- CVE-2026-40345highCVE-2026-40345 updated by NVD
- CVE-2026-55156mediumToken Optimizer MCP: Unauthenticated Path Traversal in Dashboard Session Log API Endpoints
- CVE-2026-55157highToken Optimizer MCP: OS command injection in smart_user via username in get-user-info
- CVE-2026-53708mediumCVE-2026-53708 updated by NVD
- CVE-2026-53660highCVE-2026-53660 updated by NVD
- CVE-2026-53658mediumCVE-2026-53658 updated by NVD
- CVE-2026-35219highCVE-2026-35219 updated by NVD
- CVE-2026-35511highAuthorizer: Zero-click account takeover via OAuth identity linking to unverified email accounts
- GHSA-cgvr-f65r-pjv3mediumDuplicate Advisory: Grav: Stored XSS via quoted-attribute bypass in detectXss
- GHSA-wvxr-6v52-gfmhhighDuplicate Advisory: Remote code execution via .zip file upload in Grav CMS
- GHSA-ww86-c2qf-w8fwmediumDuplicate Advisory: Missing authorization on refreshBacklink allows anonymous readers to trigger persistent se
- GHSA-p8cp-78hp-wmq8criticalDuplicate Advisory: SQL injection in backlink/mention search via unescaped stored and client input (publish mo
- GHSA-q6g5-m978-c6v9criticalDuplicate Advisory: Publish-boundary bypass via WebSocket broadcast: anonymous readers receive a live unfilter
- GHSA-rm43-82j9-r4mjhighatomic-agents-stack: Dashboard HTTP server path traversal allows arbitrary file read
- CVE-2026-55102mediumCVE-2026-55102 updated by NVD
- CVE-2026-55088mediumCVE-2026-55088 updated by NVD
- CVE-2026-55086mediumCVE-2026-55086 updated by NVD
- CVE-2026-55087mediumCVE-2026-55087 updated by NVD
- CVE-2026-55072highCVE-2026-55072 updated by NVD
- CVE-2026-55074highAnsible FreeBSD Jail Connection Plugin: Jail escape via symlink following in put_file (host-side root mv)