Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
CVE-2026-52880
  • github.com/klever-io/klever-go
Klever-Go: REST API slow-header connection exhaustion via Gin Engine.Run 14 hours ago
  • Fix available
  • Severity - 7.5 (High)
CVE-2026-47127
  • github.com/ghostfolio/ghostfolio
Ghostfolio has a Stripe subscription bypass 14 hours ago
  • Fix available
  • Severity - 6.5 (Medium)
CVE-2026-48122
  • github.com/shopify/ruby-lsp
Workspace settings can override executable and Gemfile paths used by the Ruby LSP VS Code extension 14 hours ago
  • Fix available
  • Severity - 5.4 (Medium)
CVE-2026-52879
  • github.com/klever-io/klever-go
Klever-Go: Unbounded goroutine spawn on direct-message ingress enables peer-driven DoS 14 hours ago
  • Fix available
  • Severity - 7.5 (High)
CVE-2026-48120
  • github.com/mawww/kakoune
Kakoune has a Critical RCE via Autorestore Backup Filename Injection 14 hours ago
  • Fix available
  • Severity - 8.6 (High)
CVE-2026-52878
  • github.com/klever-io/klever-go
Klever-Go: Unauthenticated nil-pointer DoS in P2P transaction validation can halt the chain 14 hours ago
  • Fix available
  • Severity - 7.5 (High)
CVE-2026-48026
  • github.com/treeverse/lakefs
lakeFS vulnerable to stored XSS in rendered markdown previews via raw HTML 14 hours ago
  • Fix available
  • Severity - 8.7 (High)
CVE-2026-49343
  • github.com/klever-io/klever-go
Klever-Go KVM: Throttler slot leak in trie account-data sync causes epoch bootstrap / state sync DoS 14 hours ago
  • Fix available
  • Severity - 5.9 (Medium)
CVE-2026-46409
  • github.com/openyak/openyak
OpenYak local API: unauthenticated CSRF chain leads to Remote Code Execution 14 hours ago
  • Fix available
  • Severity - 9.6 (Critical)
CVE-2026-48047
  • github.com/xwiki/xwiki-platform
XWiki Platform vulnerable to potential arbitrary file writing using path traversal from (subwiki) admin 14 hours ago
  • Fix available
  • Severity - 5.9 (Medium)
CVE-2026-47249
  • github.com/klever-io/klever-go
Klever-Go KVM: Hash-array amplification in P2P resolver request handling 14 hours ago
  • Fix available
  • Severity - 7.5 (High)
CVE-2026-58262
  • github.com/klever-io/klever-go
Klever-Go: PubKeysBitmap padding bits bypass the BLS signature quorum 15 hours ago
  • Fix available
  • Severity - 7.1 (High)
CVE-2026-64676
  • github.com/kata-containers/kata-containers
Kata Containers: Unauthorized mem-agent ttRPC methods let an untrusted host tamper with confidential-guest memory 15 hours ago
  • Fix available
  • Severity - 5.7 (Medium)
CVE-2026-47243
  • github.com/kata-containers/kata-containers
Kata guest escape: runtime-rs guest-root to host-root escape via virtiofs 15 hours ago
  • Fix available
  • Severity - 9.2 (Critical)
CVE-2026-48170
  • github.com/thomaspoignant/scim-patch
scimPatch vulnerable to prototype pollution via unfiltered keys in patch 15 hours ago
  • Fix available
  • Severity - 9.1 (Critical)
CVE-2026-48169
  • github.com/mervinpraison/praisonai
PraisonAI has Cross-Workspace IDOR and Privilege Escalation via Platform API 15 hours ago
  • Fix available
  • Severity - 8.8 (High)