Open Source Vulnerabilities
Microsoft.WindowsDesktop.App.Runtime.win-x64, Microsoft.WindowsDesktop.App.Runtime.win-x86, Microsoft.WindowsDesktop.App.Runtime.win-arm64, Microsoft.WindowsDesktop.App.Runtime.win-x64, Microsoft.WindowsDesktop.App.Runtime.win-x86, Microsoft.WindowsDesktop.App.Runtime.win-arm64, Microsoft.WindowsDesktop.App.Runtime.win-x64, Microsoft.WindowsDesktop.App.Runtime.win-x86, Microsoft.WindowsDesktop.App.Runtime.win-arm64
Microsoft Security Advisory CVE-2026-50646 – .NET Remote Code Execution Vulnerability
Microsoft.WindowsDesktop.App.Runtime.win-x64/ Microsoft.WindowsDesktop.App.Runtime.win-x86/ Microsoft.WindowsDesktop.App.Runtime.win-arm64/ Microsoft.WindowsDesktop.App.Runtime.win-x64/ Microsoft.WindowsDesktop.App.Runtime.win-x86/ Microsoft.WindowsDesktop.App.Runtime.win-arm64/ Microsoft.WindowsDesktop.App.Runtime.win-x64/ Microsoft.WindowsDesktop.App.Runtime.win-x86/ Microsoft.WindowsDesktop.App.Runtime.win-arm64
Microsoft Security Advisory CVE-2026-50646 – .NET Remote Code Execution Vulnerability
nltk
NLTK: Pl196xCorpusReader has quadratic ReDoS on malformed TEI blocks
nltk
NLTK: Pl196xCorpusReader has quadratic ReDoS on malformed TEI blocks
nltk
NLTK: ReDoS in nltk.tgrep via unvalidated user-supplied regular expressions
nltk
NLTK: ReDoS in nltk.tgrep via unvalidated user-supplied regular expressions
nltk
NLTK: ReDoS in nltk.text.Text.findall() via unvalidated user-supplied regular expressions
nltk
NLTK: ReDoS in nltk.text.Text.findall() via unvalidated user-supplied regular expressions
Microsoft.Native.Quic.MsQuic.OpenSSL, Microsoft.Native.Quic.MsQuic.Schannel, Microsoft.Native.Quic.MsQuic.OpenSSL, Microsoft.Native.Quic.MsQuic.Schannel
Microsoft QUIC: Remote Code Execution Vulnerability
Microsoft.Native.Quic.MsQuic.OpenSSL/ Microsoft.Native.Quic.MsQuic.Schannel/ Microsoft.Native.Quic.MsQuic.OpenSSL/ Microsoft.Native.Quic.MsQuic.Schannel
Microsoft QUIC: Remote Code Execution Vulnerability
Microsoft.Build.Tasks.Git, Microsoft.Build.Tasks.Git, Microsoft.Build.Tasks.Git, Microsoft.Build.Tasks.Git, Microsoft.SourceLink.AzureRepos.Git, Microsoft.SourceLink.AzureRepos.Git, Microsoft.SourceLink.AzureRepos.Git, Microsoft.SourceLink.AzureRepos.Git
Microsoft Security Advisory CVE-2026-62900 – .NET Information Disclosure Vulnerability
Microsoft.Build.Tasks.Git/ Microsoft.Build.Tasks.Git/ Microsoft.Build.Tasks.Git/ Microsoft.Build.Tasks.Git/ Microsoft.SourceLink.AzureRepos.Git/ Microsoft.SourceLink.AzureRepos.Git/ Microsoft.SourceLink.AzureRepos.Git/ Microsoft.SourceLink.AzureRepos.Git
Microsoft Security Advisory CVE-2026-62900 – .NET Information Disclosure Vulnerability
vllm
vLLM: Cross-User Data Leak Vulnerability
libhtml-formhandler-perl, libhtml-formhandler-perl, libhtml-formhandler-perl
libhtml-formhandler-perl/ libhtml-formhandler-perl/ libhtml-formhandler-perl
libhtml-formhandler-perl, libhtml-formhandler-perl, libhtml-formhandler-perl
libhtml-formhandler-perl/ libhtml-formhandler-perl/ libhtml-formhandler-perl
libhtml-formhandler-perl, libhtml-formhandler-perl, libhtml-formhandler-perl
libhtml-formhandler-perl/ libhtml-formhandler-perl/ libhtml-formhandler-perl
OpenTelemetry.Resources.Host vulnerable to arbitrary code execution via local PATH hijacking on macOS
OpenTelemetry.Resources.Host vulnerable to arbitrary code execution via local PATH hijacking on macOS
libhtml-formhandler-perl, libhtml-formhandler-perl, libhtml-formhandler-perl, libhtml-formhandler-perl, libhtml-formhandler-perl, libhtml-formhandler-perl
libhtml-formhandler-perl/ libhtml-formhandler-perl/ libhtml-formhandler-perl/ libhtml-formhandler-perl/ libhtml-formhandler-perl/ libhtml-formhandler-perl
libhtml-formhandler-perl, libhtml-formhandler-perl, libhtml-formhandler-perl, libhtml-formhandler-perl, libhtml-formhandler-perl, libhtml-formhandler-perl
libhtml-formhandler-perl/ libhtml-formhandler-perl/ libhtml-formhandler-perl/ libhtml-formhandler-perl/ libhtml-formhandler-perl/ libhtml-formhandler-perl
libhtml-formhandler-perl, libhtml-formhandler-perl, libhtml-formhandler-perl, libhtml-formhandler-perl, libhtml-formhandler-perl, libhtml-formhandler-perl
libhtml-formhandler-perl/ libhtml-formhandler-perl/ libhtml-formhandler-perl/ libhtml-formhandler-perl/ libhtml-formhandler-perl/ libhtml-formhandler-perl
libhtml-formhandler-perl, libhtml-formhandler-perl, libhtml-formhandler-perl
libhtml-formhandler-perl/ libhtml-formhandler-perl/ libhtml-formhandler-perl
libhtml-formhandler-perl, libhtml-formhandler-perl, libhtml-formhandler-perl, libhtml-formhandler-perl, libhtml-formhandler-perl, libhtml-formhandler-perl
libhtml-formhandler-perl/ libhtml-formhandler-perl/ libhtml-formhandler-perl/ libhtml-formhandler-perl/ libhtml-formhandler-perl/ libhtml-formhandler-perl
HTML::FormHandler versions before 0.410002 for Perl render field attributes into HTML without escaping using the process_attrs method
HTML::FormHandler versions before 0.410002 for Perl render field attributes into HTML without escaping using the process_attrs method
HTML::FormHandler versions before 0.410002 for Perl render some error messages into HTML without escaping
HTML::FormHandler versions before 0.410002 for Perl render some error messages into HTML without escaping
HTML::FormHandler versions before 0.410002 for Perl render option group labels and radio button labels into HTML without escaping
HTML::FormHandler versions before 0.410002 for Perl render option group labels and radio button labels into HTML without escaping
HTML::FormHandler versions before 0.410000 for Perl allow cross-site scripting via a submitted value rendered unescaped in an error message
HTML::FormHandler versions before 0.410000 for Perl allow cross-site scripting via a submitted value rendered unescaped in an error message
Open-Web-Analytics Controller Controller.php checkCapabilityAndAuthenticateUser improper authentication
Open-Web-Analytics Controller Controller.php checkCapabilityAndAuthenticateUser improper authentication
gitpython
GitPython: TagReference.create positional reference bypasses kwargs-only --file guard, enabling arbitrary file read (incomplete fix of 3af0c251)
gitpython
GitPython: TagReference.create positional reference bypasses kwargs-only --file guard, enabling arbitrary file read (incomplete fix of 3af0c251)
Stored Cross-Site Scripting via Vega Expression Function Bypass in OpenSearch Dashboards
Stored Cross-Site Scripting via Vega Expression Function Bypass in OpenSearch Dashboards
moltis-org moltis vault.rs vault_recovery_handler missing authentication
moltis-org moltis vault.rs vault_recovery_handler missing authentication
opengeos GeoLibre _is_within_roots server-side request forgery
opengeos GeoLibre _is_within_roots server-side request forgery
seakee CPA-Manager-Plus HTTP handler.go CPAResource improper authorization
seakee CPA-Manager-Plus HTTP handler.go CPAResource improper authorization
Cesanta mJS mjs_tok.c skip_spaces_and_comments heap-based overflow
Cesanta mJS mjs_tok.c skip_spaces_and_comments heap-based overflow
gitpython
GitPython: clone_from()/clone() omit --separate-git-dir from unsafe_git_clone_options, enabling arbitrary git-directory creation outside the destination
gitpython
GitPython: clone_from()/clone() omit --separate-git-dir from unsafe_git_clone_options, enabling arbitrary git-directory creation outside the destination
gitpython
GitPython: Incomplete unsafe_git_revision_options denylist omits --contents/-S, enabling arbitrary file read via Repo.blame()
gitpython
GitPython: Incomplete unsafe_git_revision_options denylist omits --contents/-S, enabling arbitrary file read via Repo.blame()
gitpython
GitPython: Dormant multi-line git-config values are corrupted into live injected directives (e.g. core.hooksPath) on any unrelated GitConfigParser write, enabling RCE
gitpython
GitPython: Dormant multi-line git-config values are corrupted into live injected directives (e.g. core.hooksPath) on any unrelated GitConfigParser write, enabling RCE
@astrojs/prism, @astrojs/webapi, astro, create-astro
TuxCare security update for 4 packages (1 CVE)
@astrojs/prism/ @astrojs/webapi/ astro/ create-astro
TuxCare security update for 4 packages (1 CVE)
gitpython
GitPython: Arbitrary local file content disclosure via [include] directive in untrusted .gitmodules (SubmoduleConfigParser never disables merge_includes)
gitpython
GitPython: Arbitrary local file content disclosure via [include] directive in untrusted .gitmodules (SubmoduleConfigParser never disables merge_includes)
Microsoft.DiaSymReader.Native
Duplicate Advisory: Microsoft Security Advisory CVE-2026-71328 – .NET and Visual Studio Remote Code Execution Vulnerability
Microsoft.DiaSymReader.Native
Duplicate Advisory: Microsoft Security Advisory CVE-2026-71328 – .NET and Visual Studio Remote Code Execution Vulnerability
Microsoft.DiaSymReader.Native
Duplicate Advisory: Microsoft Security Advisory CVE-2026-69522 – .NET and Visual Studio Remote Code Execution Vulnerability
Microsoft.DiaSymReader.Native
Duplicate Advisory: Microsoft Security Advisory CVE-2026-69522 – .NET and Visual Studio Remote Code Execution Vulnerability
Microsoft.DiaSymReader.Native
Duplicate Advisory: Microsoft Security Advisory CVE-2026-69439 – .NET and Visual Studio Elevation of Privilege Vulnerability
Microsoft.DiaSymReader.Native
Duplicate Advisory: Microsoft Security Advisory CVE-2026-69439 – .NET and Visual Studio Elevation of Privilege Vulnerability
Microsoft.AspNetCore.Server.IISIntegration, Microsoft.AspNetCore.Server.IISIntegration, Microsoft.AspNetCore.Server.IISIntegration, Microsoft.AspNetCore.Server.IISIntegration
Duplicate Advisory: Microsoft Security Advisory CVE-2026-69304 – ASP.NET Core Denial of Service Vulnerability
Microsoft.AspNetCore.Server.IISIntegration/ Microsoft.AspNetCore.Server.IISIntegration/ Microsoft.AspNetCore.Server.IISIntegration/ Microsoft.AspNetCore.Server.IISIntegration
Duplicate Advisory: Microsoft Security Advisory CVE-2026-69304 – ASP.NET Core Denial of Service Vulnerability
imagemagick, imagemagick, imagemagick, imagemagick, imagemagick, imagemagick
imagemagick vulnerabilities
imagemagick/ imagemagick/ imagemagick/ imagemagick/ imagemagick/ imagemagick
imagemagick vulnerabilities
