Browse vulnerabilities
204 results
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2025-30066 | Act now | 72.1% | — | ● | tj-actions/changed-files GitHub Action contains an embedded malicious code vulnerability t… |
| CVE-2025-30154 | Act now | 2.4% | — | ● | reviewdog action-setup GitHub Action contains an embedded malicious code vulnerability tha… |
| CVE-2025-56005 | High | 19.1% | 9.8 | An undocumented and unsafe feature in the PLY (Python Lex-Yacc) library 3.11 allows Remote… | |
| CVE-2026-34243 | High | 2.8% | 9.8 | wenxian is a tool to generate BIBTEX files from given identifiers (DOI, PMID, arXiv ID, or… | |
| CVE-2026-4800 | Medium | 2.6% | 8.1 | Impact: The fix for CVE-2021-23337 (https://github.com/advisories/GHSA-35jh-r3h4-6jhm) ad… | |
| CVE-2026-76761 | Medium | 2.1% | 7.3 | A vulnerability was identified in chenhg5 cc-connect up to 1.4.1. This affects the functio… | |
| CVE-2026-44359 | Medium | 1.8% | 10.0 | Meshtastic is an open source mesh networking solution. Prior to version 2.7.21.1370b23, th… | |
| CVE-2024-1394 | Medium | 1.5% | 7.5 | A memory leak flaw was found in Golang in the RSA encrypting/decrypting code, which might … | |
| CVE-2026-48168 | Medium | 1.5% | 10.0 | PraisonAI is a multi-agent teams system. In versions prior to 4.6.40, the bundled Claude G… | |
| CVE-2024-3727 | Medium | 1.3% | 8.3 | A flaw was found in the github.com/containers/image library. This flaw allows attackers to… | |
| CVE-2026-61483 | Medium | 1.0% | 7.5 | ** UNSUPPORTED WHEN ASSIGNED ** Uncontrolled Recursion vulnerability in Apache Lucy. Th… | |
| CVE-2026-72867 | Medium | 1.0% | 9.9 | Dokploy is a free, self-hostable Platform as a Service (PaaS). From 0.29.3 until 0.29.13, … | |
| CVE-2026-86492 | Medium | 0.9% | 8.5 | In JetBrains YouTrack before 2026.2.18634 a shared token cache allowed cross-tenant theft … | |
| CVE-2026-41109 | Medium | 0.9% | 8.8 | Improper neutralization of special elements in output used by a downstream component ('inj… | |
| CVE-2026-33815 | Medium | 0.9% | 9.8 | Memory-safety vulnerability in github.com/jackc/pgx/v5. | |
| CVE-2026-33816 | Medium | 0.9% | 9.8 | Memory-safety vulnerability in github.com/jackc/pgx/v5. | |
| CVE-2026-76851 | Medium | 0.8% | 8.8 | A Server-Side Request Forgery (SSRF) vulnerability was identified in GitHub Enterprise Ser… | |
| CVE-2026-82923 | Medium | 0.8% | 9.8 | The AI Website Builder WordPress plugin (GitHub build) 1.0.0 does not perform any authoris… | |
| CVE-2026-19349 | Medium | 0.8% | 9.8 | Lemonldap::NG::Portal versions from 2.0.0 before 2.16.9, from 2.17.0 before 2.21.5, from 2… | |
| CVE-2026-45618 | Medium | 0.8% | 10.0 | LiquidJS is a Shopify/GitHub Pages compatible template engine. Prior to version 10.26.0, i… | |
| CVE-2026-42298 | Medium | 0.8% | 10.0 | Postiz is an AI social media scheduling tool. Prior to commit da44801, a "Pwn Request" vul… | |
| CVE-2026-63043 | Medium | 0.8% | 7.5 | Relative Path Traversal vulnerability in Apache InLong. Arbitrary file read from the Agent… | |
| CVE-2026-61486 | Medium | 0.8% | 9.8 | ** UNSUPPORTED WHEN ASSIGNED ** Stack-based Buffer Overflow vulnerability in Apache Lucy. … | |
| CVE-2026-61484 | Medium | 0.8% | 9.8 | ** UNSUPPORTED WHEN ASSIGNED ** Deserialization of Untrusted Data vulnerability in Apache … | |
| CVE-2026-17556 | Medium | 0.8% | 9.1 | A path traversal vulnerability was identified in GitHub Enterprise Server that allowed an … | |
| CVE-2026-47427 | Medium | 0.8% | 7.5 | GitHub MCP Server is GitHub's official MCP Server. Prior to 1.1.0, the CompletionsHandler … | |
| CVE-2026-15996 | Medium | 0.8% | 7.5 | A denial of service vulnerability was identified in GitHub Enterprise Server that allowed … | |
| CVE-2026-46412 | Medium | 0.8% | 10.0 | @beproduct/nestjs-auth is a NestJS authentication module for BeProduct IDS (Identity Serve… | |
| CVE-2026-8135 | Medium | 0.7% | 7.2 | Concrete CMS 9.5.0 and below is vulnerable to Remote Code Execution due to insecure deser… | |
| CVE-2026-76139 | Medium | 0.7% | 8.0 | A flaw was found in acm-operator-bundle. The build process for this component downloads an… | |
| CVE-2026-41249 | Medium | 0.7% | 8.2 | CoreShop is a Pimcore enhanced eCommerce solution. In versions 5.0.1 through 5.1.0-beta.1,… | |
| CVE-2026-84423 | Medium | 0.7% | 7.3 | A vulnerability has been found in Casdoor up to 4.0.0. This affects an unknown function of… | |
| CVE-2026-63490 | Medium | 0.7% | 7.5 | Handlebars.java provides logic-less and semantic Mustache templates with Java. Prior to 4.… | |
| CVE-2026-63037 | Medium | 0.7% | 9.8 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulne… | |
| CVE-2026-63038 | Medium | 0.7% | 9.8 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulne… | |
| CVE-2026-63039 | Medium | 0.7% | 9.8 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulne… | |
| CVE-2026-11325 | Medium | 0.7% | 8.8 | Description Cloudflare was recently notified by external researchers of vulnerabilities… | |
| CVE-2026-63046 | Medium | 0.7% | 8.8 | Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnera… | |
| CVE-2026-54752 | Medium | 0.7% | 9.6 | NetBox Device Type Library is a collection of community-sourced device type definitions fo… | |
| CVE-2026-93559 | Medium | 0.7% | 7.3 | A vulnerability was identified in Forget-C Jellyfish AI Short Drama Studio 0.1.0-alpha/0.2… | |
| CVE-2026-63040 | Medium | 0.6% | 8.1 | Files or Directories Accessible to External Parties vulnerability in Apache InLong. Stream… | |
| CVE-2026-63042 | Medium | 0.6% | 8.1 | Files or Directories Accessible to External Parties vulnerability in Apache InLong. Any us… | |
| CVE-2025-8194 | Medium | 0.6% | 7.5 | There is a defect in the CPython “tarfile” module affecting the “TarFile” extraction and e… | |
| CVE-2026-59960 | Medium | 0.6% | 7.5 | Argos JavaScript provides official Argos SDKs for JavaScript. Prior to Argos core package … | |
| CVE-2026-65675 | Medium | 0.6% | 7.1 | No cwe for this issue in Visual Studio Code CoPilot Chat Extension allows an unauthorized … | |
| CVE-2026-69222 | Medium | 0.6% | 7.5 | LiquidJS is a Shopify / GitHub Pages compatible template engine in pure JavaScript. Prior … | |
| CVE-2026-74742 | Medium | 0.6% | 7.5 | In the Linux kernel, the following vulnerability has been resolved: veth: fix queue index… | |
| CVE-2023-4781 | Medium | 0.6% | 7.8 | Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1873. | |
| CVE-2026-54916 | Medium | 0.6% | 8.8 | NetBox Device Type Library is a collection of community-sourced device type definitions fo… | |
| CVE-2026-71620 | Medium | 0.6% | 8.1 | File Upload vulnerability in Zhao-github ApiAdmin v.5.0.1 allows a remote attacker to exec… |
Page 1 of 5
Next →