Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
EEF-CVE-2026-23940
  • github.com/hexpm/hexpm.git
Denial of Service via Oversized Package Upload 10 hours ago
  • Fix available
  • Severity - 7.1 (High)
EEF-CVE-2026-23941
  • github.com/erlang/otp
Request smuggling via first-wins Content-Length parsing in inets httpd 17 hours ago
  • Fix available
  • Severity - 7.0 (High)
EEF-CVE-2026-23943
  • github.com/erlang/otp
Pre-auth SSH DoS via unbounded zlib inflate 17 hours ago
  • Fix available
  • Severity - 6.9 (Medium)
EEF-CVE-2026-23942
  • github.com/erlang/otp
SFTP root escape via component-agnostic prefix check in ssh_sftpd 17 hours ago
  • Fix available
  • Severity - 5.3 (Medium)
PSF-2026-10
  • github.com/python/cpython
See record for full details yesterday
  • No fix available
CVE-2026-31875
  • github.com/parse-community/parse-server
Parse Server MFA recovery codes not consumed after use 2 days ago
  • Fix available
  • Severity - 8.2 (High)
CVE-2026-31872
  • github.com/parse-community/parse-server
Parse Server has a protected fields bypass via dot-notation in query and sort 2 days ago
  • Fix available
  • Severity - 8.7 (High)
CVE-2026-31871
  • github.com/parse-community/parse-server
Parse Server has a SQL Injection via dot-notation sub-key name in `Increment` operation on PostgreSQL 2 days ago
  • Fix available
  • Severity - 9.3 (Critical)
CVE-2026-31870
  • github.com/yhirose/cpp-httplib
cpp-httplib Affected by Remote Process Crash via Malformed Content-Length Response Header 2 days ago
  • Fix available
  • Severity - 7.5 (High)
CVE-2026-31868
  • github.com/parse-community/parse-server
Parse Server has Stored XSS via file upload of HTML-renderable file types 2 days ago
  • Fix available
  • Severity - 6.3 (Medium)
CVE-2026-31856
  • github.com/parse-community/parse-server
Parse Server has a SQL injection via `Increment` operation on nested object field in PostgreSQL 2 days ago
  • Fix available
  • Severity - 9.3 (Critical)
CVE-2026-31840
  • github.com/parse-community/parse-server
Parse Server has a SQL injection via dot-notation field name in PostgreSQL 2 days ago
  • Fix available
  • Severity - 9.3 (Critical)
CVE-2026-31813
  • github.com/supabase/auth
Supabase Auth has insecure Apple and Azure authentication with ID tokens 2 days ago
  • Fix available
  • Severity - 4.8 (Medium)
CVE-2026-30868
  • github.com/opnsense/core
Cross-Site Request Forgery (CSRF) in opnsense/core 2 days ago
  • Fix available
  • Severity - 6.3 (Medium)
CVE-2026-30239
  • github.com/opf/openproject
OpenProject has a Permission Check bypass on Budget deletion allows reassignment of WorkPackages into other budgets 2 days ago
  • Fix available
  • Severity - 6.5 (Medium)
CVE-2026-30236
  • github.com/opf/openproject
OpenProject users that are not project members can be used to calculate Labor Budget, leaking their global hourly rate 2 days ago
  • Fix available
  • Severity - 4.3 (Medium)