Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
CVE-2026-55232
  • github.com/givanz/vvveb
Vvveb: Server-side request forgery in Vvveb via IPv6 bypass of validateUrl() in editor oEmbed proxy 10 hours ago
  • Fix available
  • Severity - 7.6 (High)
CVE-2026-55230
  • github.com/givanz/vvveb
Vvveb: Stored XSS in Vvveb via sanitizeHTML() filter bypass using a quoted greater-than character 10 hours ago
  • Fix available
  • Severity - 8.7 (High)
CVE-2026-55231
  • github.com/givanz/vvveb
Vvveb: Path traversal in Vvveb via sanitizeFileName() bypass enables arbitrary file read and delete through backup tools 10 hours ago
  • Fix available
  • Severity - 7.2 (High)
CVE-2026-104059
  • github.com/lektor/lektor
Lektor 3.3.14 CSRF via Admin API Endpoints 10 hours ago
  • No fix available
  • Severity - 7.0 (High)
CVE-2026-55083
  • github.com/dhis2/dhis2-core
DHIS2: Unsafe Java Deserialization - Remote Code Execution (RCE) 11 hours ago
  • Fix available
  • Severity - 9.1 (Critical)
CVE-2026-103923
  • github.com/katex/katex
KaTeX: Existing prototype pollution can bypass trust restrictions 11 hours ago
  • Fix available
  • Severity - 2.1 (Low)
CVE-2026-68496
  • github.com/fasterxml/jackson-dataformats-binary
jackson-dataformats-binary: Smile parser does not enforce StreamReadConstraints.maxNameLength, enabling memory-exhaustion denial of service 11 hours ago
  • No fix available
  • Severity - 7.5 (High)
CVE-2026-68495
  • github.com/fasterxml/jackson-dataformats-binary
jackson-dataformats-binary: CBOR parser does not enforce StreamReadConstraints.maxNameLength, enabling memory-exhaustion denial of service 11 hours ago
  • No fix available
  • Severity - 7.5 (High)
CVE-2026-103922
  • github.com/ionic-team/capacitor
Capacitor Android and iOS: remote content can be loaded at the app origin via the internal HTTP proxy path 11 hours ago
  • Fix available
  • Severity - 9.3 (Critical)
CVE-2023-54404
  • github.com/colinhacks/zod
Zod 4.6.5 Uncontrolled Resource Consumption via Array Validation 11 hours ago
  • No fix available
  • Severity - 8.2 (High)
CVE-2026-73976
  • github.com/4turesearchdata/djehuty
djehuty: Unauthenticated SPARQL injection in the search API (`order`, `operator`, `key`) 11 hours ago
  • Fix available
  • Severity - 7.1 (High)
CVE-2026-73975
  • github.com/4turesearchdata/djehuty
djehuty: Authenticated SPARQL injection in session editing allows writing arbitrary RDF triples 12 hours ago
  • Fix available
  • Severity - 8.4 (High)
CVE-2026-77387
  • github.com/geopy/geopy
geopy: Regular Expression Denial of Service (ReDoS) in geopy.Point 12 hours ago
  • Fix available
  • Severity - 4.0 (Medium)
CVE-2026-103921
  • github.com/ardatan/graphql-tools
GraphQL Tools: TLS Certificate Validation Disabled in Legacy GraphQL WebSocket Executor 12 hours ago
  • Fix available
  • Severity - 7.4 (High)
CVE-2026-101322
  • github.com/eclipse-basyx/basyx-aas-web-ui
See record for full details 13 hours ago
  • Fix available
  • Severity - 8.3 (High)
CVE-2026-94620
  • github.com/foundation50/classroom50
Classroom 50 vulnerable to arbitrary file overwrite on the teacher's machine via symlink in a student repo (gh teacher download) 13 hours ago
  • Fix available
  • Severity - 9.4 (Critical)