Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
EEF-CVE-2026-94201
  • Hex/ash
  • github.com/ash-project/ash
Filtering an :atom attribute with unsafe_to_atom? can exhaust the BEAM atom table in Ash 7 hours ago
  • Fix available
  • Severity - 8.2 (High)
CVE-2026-105295
  • github.com/gitahead/gitahead
GitAhead 2.5.0 through 2.7.1 Unverified Update Installation and TLS Bypass yesterday
  • No fix available
  • Severity - 7.7 (High)
CVE-2026-105294
  • github.com/legcord/legcord
Legcord 1.1.0 through 1.3.0 Chromium Switch Injection via settings.setConfig yesterday
  • No fix available
  • Severity - 9.1 (Critical)
CVE-2026-105293
  • github.com/legcord/legcord
Legcord 1.1.0 through 1.3.0 Path Traversal via Theme IPC Handlers yesterday
  • No fix available
  • Severity - 9.2 (Critical)
CVE-2026-105292
  • github.com/chaterm/chaterm
Chaterm before 0.12.1 Login CSRF via chaterm:// OAuth Callback yesterday
  • Fix available
  • Severity - 6.0 (Medium)
CVE-2026-105223
  • github.com/maclof/kubernetes-client
maclof kubernetes-client 0.17.0 before 0.32.0 Disabled TLS Certificate Verification yesterday
  • Fix available
  • Severity - 9.1 (Critical)
CVE-2026-105174
  • github.com/gerapy/gerapy
Gerapy Project Management views.py project_create path traversal yesterday
  • No fix available
  • Severity - 2.1 (Low)
CVE-2026-105222
  • github.com/alexpechkarev/google-maps
alexpechkarev/google-maps through 12.16 Disabled TLS Certificate Verification via ssl_verify_peer yesterday
  • No fix available
  • Severity - 9.1 (Critical)
CVE-2026-105221
  • github.com/defunkt/gist
Gist RubyGem before 6.1.0 Disabled TLS Certificate Verification yesterday
  • Fix available
  • Severity - 9.1 (Critical)
CVE-2026-105220
  • github.com/klembot/twinejs
Twine 2 Desktop through 2.12.0 Arbitrary Code Execution via Imported Story Files yesterday
  • No fix available
  • Severity - 8.5 (High)
CVE-2026-105165
  • github.com/devopspolis/secrets-replicator
devopspolis secrets-replicator AssumeRole handler.py process_single_secret permission assignment yesterday
  • No fix available
  • Severity - 5.3 (Medium)
CVE-2026-105164
  • github.com/nasa/cfs
NASA cFS cfe_fs_api.c CFE_FS_ParseInputFileNameEx out-of-bounds yesterday
  • No fix available
  • Severity - 5.1 (Medium)
CVE-2026-105163
  • github.com/crossplane/crossplane-runtime
crossplane crossplane-runtime ImageConfig client.go Get toctou yesterday
  • No fix available
  • Severity - 6.9 (Medium)
CVE-2026-105219
  • github.com/mwilliamson/mammoth.js
Mammoth.js 1.3.0 before 1.12.3 ReDoS via Style Map Tokeniser yesterday
  • Fix available
  • Severity - 8.7 (High)
CVE-2026-105218
  • github.com/go-pay/gopay
gopay before 1.5.119 Disabled TLS Certificate Verification in xhttp Client yesterday
  • Fix available
  • Severity - 9.1 (Critical)
CVE-2026-105217
  • github.com/cockpit-hq/cockpit
Cockpit CMS 2.12.0 before 2.14.1 Disabled TLS Verification via cron.php yesterday
  • Fix available
  • Severity - 2.3 (Low)