Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
EEF-CVE-2026-21622
  • github.com/hexpm/hexpm.git
Password Reset Tokens Do Not Expire 2 days ago
  • Fix available
  • Severity - 9.5 (Critical)
EEF-CVE-2026-21621
  • github.com/hexpm/hexpm.git
Improper Scope Enforcement in OAuth client_credentials Flow Allows Read-Only API Key to Escalate to Full Access 2 days ago
  • Fix available
  • Severity - 7.0 (High)
PSF-2026-9
  • github.com/python/cpython
See record for full details 3 days ago
  • Fix available
CVE-2026-25884
  • github.com/exiv2/exiv2
Exiv2: Out-of-bounds read in CrwMap::decode0x0805 5 days ago
  • Fix available
  • Severity - 2.7 (Low)
CVE-2026-27596
  • github.com/exiv2/exiv2
Exiv2: Integer Underflow in LoaderNative::getData() Causes Heap Buffer Overflow 5 days ago
  • Fix available
  • Severity - 2.7 (Low)
CVE-2026-27631
  • github.com/exiv2/exiv2
Exiv2: Uncaught exception - cannot create std::vector larger than max_size() 5 days ago
  • Fix available
  • Severity - 2.7 (Low)
CVE-2026-21882
  • github.com/asfhtgkdavid/theshit
theshit's Improper Privilege Dropping Allows Local Privilege Escalation via Command Re-execution 5 days ago
  • Fix available
  • Severity - 8.4 (High)
CVE-2026-25477
  • github.com/toeverything/affine
AFFiNE: Open Redirect via Regex Bypass in redirect-proxy 5 days ago
  • Fix available
  • Severity - 6.9 (Medium)
CVE-2026-21853
  • github.com/toeverything/affine
AFFiNE: One-click Remote Code Execution through Custom URL Handling 5 days ago
  • Fix available
  • Severity - 8.8 (High)
CVE-2025-64427
  • github.com/icewhaletech/zimaos
ZimaOS is vulnerable to Server-Side Request Forgery (SSRF) 5 days ago
  • Fix available
  • Severity - 7.1 (High)
CVE-2026-28286
  • github.com/icewhaletech/zimaos
ZimaOS: Unauthorized Creation of Files/Folders in Restricted System Directories via API 5 days ago
  • No fix available
  • Severity - 8.5 (High)
CVE-2026-28401
  • github.com/nocodb/nocodb
NocoDB: Stored Cross-Site Scripting via Rich Text Cells 5 days ago
  • Fix available
  • Severity - 5.3 (Medium)
CVE-2026-28399
  • github.com/nocodb/nocodb
NocoDB: SQL Injection via DATEADD Formula 5 days ago
  • Fix available
  • Severity - 6.2 (Medium)
CVE-2026-28398
  • github.com/nocodb/nocodb
NocoDB: Stored Cross-Site Scripting via Comments and Rich Text Cells 5 days ago
  • Fix available
  • Severity - 5.3 (Medium)
CVE-2026-28397
  • github.com/nocodb/nocodb
NocoDB: Stored Cross-Site Scripting via Comments 5 days ago
  • Fix available
  • Severity - 5.3 (Medium)
CVE-2026-28396
  • github.com/nocodb/nocodb
NocoDB: Refresh Tokens Not Revoked on Password Reset 5 days ago
  • Fix available
  • Severity - 4.9 (Medium)