Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
CVE-2026-48791
  • github.com/sigstore/sigstore-java
Sigstore Java has a vulnerability with bundle verification of integratedTime yesterday
  • No fix available
  • Severity - 2.0 (Low)
CVE-2026-46382
  • github.com/meeting-room-booking-system/mrbs-code
Meeting Room Booking System has server-side request forgery in import functionality yesterday
  • Fix available
  • Severity - 8.7 (High)
CVE-2026-46688
  • github.com/meeting-room-booking-system/mrbs-code
Meeting Room Booking System has an unauthenticated open redirect yesterday
  • Fix available
  • Severity - 6.9 (Medium)
CVE-2026-49473
  • github.com/cedar-policy/authorization-for-expressjs
@cedar-policy/authorization-for-expressjs has an authorization bypass via query string manipulation yesterday
  • Fix available
  • Severity - 8.8 (High)
CVE-2026-50544
  • github.com/northebridge/luminalshine
NortheBridge/luminalshine has Incorrect Permission Assignment for Critical Resource and Creation of Temporary File in Directory with Insecure Permissions yesterday
  • Fix available
  • Severity - 6.3 (Medium)
CVE-2026-49819
  • github.com/seriousm4x/upsnap
UpSnap - Unauthenticated Initial-Superuser Takeover Chains to Root RCE via wake_cmd yesterday
  • Fix available
  • Severity - 9.8 (Critical)
CVE-2026-17431
  • github.com/kingpong/perl-pdf-webkit
PDF::WebKit versions through 1.2 for Perl allow OS command injection via a 2-arg open() of the output path in to_pdf and of stylesheet paths in _style_tag_for yesterday
  • No fix available
CVE-2026-16770
  • github.com/kingpong/perl-pdf-webkit
PDF::WebKit versions through 1.2 for Perl allow argument injection into wkhtmltopdf via meta tags in the source document yesterday
  • No fix available
CVE-2026-49481
  • github.com/seriousm4x/upsnap
UpSnap vulnerable to Remote Code Execution via IP Field Template Injection in wake_cmd/shutdown_cmd yesterday
  • Fix available
  • Severity - 9.6 (Critical)
CVE-2026-71194
  • opendev.org/openstack/designate
See record for full details yesterday
  • Fix available
  • Severity - 6.8 (Medium)
CVE-2026-47717
  • github.com/frangoteam/fuxa
FUXA's Unauthenticated Project Data Disclosure Exposes Server-Side Scripts and Device Configurations yesterday
  • No fix available
  • Severity - 7.5 (High)
CVE-2026-71193
  • opendev.org/openstack/designate
See record for full details yesterday
  • Fix available
  • Severity - 9.6 (Critical)
CVE-2026-73501
  • github.com/getkin/kin-openapi
kin-openapi: ValidationHandler.Load() Fail-Open Authentication Bypass via NoopAuthenticationFunc Default yesterday
  • Fix available
  • Severity - 9.1 (Critical)
CVE-2026-73500
  • github.com/etcd-io/etcd
etcd: `tlsListener.acceptLoop` spawns unbounded handshake goroutines with no deadline yesterday
  • Fix available
  • Severity - 8.7 (High)
CVE-2026-73499
  • github.com/etcd-io/etcd
etcd: Watch API authorization bypass via open-ended range requests yesterday
  • Fix available
  • Severity - 7.1 (High)
CVE-2026-73498
  • github.com/sooperset/mcp-atlassian
MCP Atlassian is a Model Context Protocol (MCP): Arbitrary file read via missing path validation in confluence_upload_attachment yesterday
  • Fix available
  • Severity - 7.7 (High)