Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
EEF-CVE-2026-94206
  • Hex/cloak
  • Hex/cloak_ecto
  • github.com/danielberkompas/cloak
  • github.com/danielberkompas/cloak_ecto
Cloak PBKDF2 field ignores the configured iteration count and runs only :size rounds 3 hours ago
  • Fix available
  • Severity - 6.3 (Medium)
EEF-CVE-2026-95105
  • Hex/cloak
  • github.com/danielberkompas/cloak
Cloak AES-CTR cipher lacks ciphertext authentication, allowing chosen-plaintext forgery by bit flipping 3 hours ago
  • No fix available
  • Severity - 8.2 (High)
CVE-2026-105571
  • github.com/lilishop/lilishop
PickMall Lilishop Mobile Binding bindMobile improper authorization 9 hours ago
  • No fix available
  • Severity - 5.5 (Medium)
CVE-2026-105487
  • github.com/yogeshojha/rengine
yogeshojha reNgine listTargets Endpoint tasks.py subdomain_discovery os command injection 10 hours ago
  • No fix available
  • Severity - 2.1 (Low)
CVE-2026-105486
  • github.com/ossrs/srs
OSSRS srs System API api.go systemAPI.Run missing authentication 10 hours ago
  • No fix available
  • Severity - 5.5 (Medium)
CVE-2026-105786
  • github.com/laurent22/joplin
Joplin: Unauthenticated account takeover via an attacker-chosen application-authorisation identifier 12 hours ago
  • Fix available
  • Severity - 8.5 (High)
CVE-2026-105785
  • github.com/laurent22/joplin
Joplin Server password reset accepts tokens issued for unrelated purposes 12 hours ago
  • Fix available
  • Severity - 4.8 (Medium)
CVE-2026-105784
  • github.com/laurent22/joplin
Joplin whiteboard card rendering allows CSS injection into application chrome 12 hours ago
  • Fix available
  • Severity - 4.6 (Medium)
CVE-2026-105783
  • github.com/laurent22/joplin
Joplin Web Clipper pairing allows cross-origin theft of a permanent API token 12 hours ago
  • Fix available
  • Severity - 8.0 (High)
CVE-2026-105782
  • github.com/scrapy/scrapy
Scrapy: Arbitrary Module Import via Referrer-Policy Header in RefererMiddleware 12 hours ago
  • Fix available
  • Severity - 7.5 (High)
CVE-2026-105764
  • github.com/immich-app/immich
Immich: Authenticated SVG upload reaches ImageMagick coders and enables RCE 12 hours ago
  • Fix available
  • Severity - 7.7 (High)
CVE-2026-105763
  • github.com/twentyhq/twenty
Twenty: Plaintext IMAP/SMTP/CalDAV password disclosure to any workspace member via /metadata GraphQL 12 hours ago
  • Fix available
  • Severity - 9.6 (Critical)
CVE-2026-105762
  • github.com/langgenius/dify
Dify: Unauthenticated Server-Side Request Forgery in /console/api/remote-files/upload endpoint 12 hours ago
  • Fix available
  • Severity - 8.3 (High)
CVE-2026-105761
  • github.com/langgenius/dify
Dify: IDOR in AppMCPServer PUT Endpoint Allows Modification of Other Apps' MCP Servers 12 hours ago
  • Fix available
  • Severity - 7.1 (High)
CVE-2026-105760
  • github.com/vllm-project/vllm
vLLM: GLMGA video sampling permits request-driven CPU and memory exhaustion 12 hours ago
  • Fix available
  • Severity - 5.3 (Medium)
CVE-2026-105759
  • github.com/vllm-project/vllm
vLLM: Unbounded Prometheus label cardinality from attacker-controlled HTTP method tokens in the vLLM Rust frontend metrics middleware (unauthenticated denial of service) 12 hours ago
  • Fix available
  • Severity - 5.9 (Medium)