Open Source Vulnerabilities

    Dashboard / Open Source Vulnerabilities

    UBUNTU-CVE-2026-82070
    No fix available
    Packages

    mongodb, mongodb, mongodb, mongodb

    Summary

    Published
    8 Sept 2026
    UBUNTU-CVE-2026-82065
    No fix available
    Packages

    mongodb, mongodb, mongodb, mongodb

    Summary

    Published
    8 Sept 2026
    UBUNTU-CVE-2026-82062
    No fix available
    Packages

    mongodb, mongodb, mongodb, mongodb

    Summary

    Published
    8 Sept 2026
    UBUNTU-CVE-2026-82060
    No fix available
    Packages

    mongodb, mongodb, mongodb, mongodb

    Summary

    Published
    8 Sept 2026
    UBUNTU-CVE-2026-82059
    No fix available
    Packages

    mongodb, mongodb, mongodb, mongodb

    Summary

    Published
    8 Sept 2026
    UBUNTU-CVE-2026-82058
    No fix available
    Packages

    mongodb, mongodb, mongodb, mongodb

    Summary

    Published
    8 Sept 2026
    UBUNTU-CVE-2026-82057
    No fix available
    Packages

    mongodb, mongodb, mongodb, mongodb

    Summary

    Published
    8 Sept 2026
    UBUNTU-CVE-2026-82056
    No fix available
    Packages

    mongodb, mongodb, mongodb, mongodb

    Summary

    Published
    8 Sept 2026
    UBUNTU-CVE-2026-82055
    No fix available
    Packages

    mongodb, mongodb, mongodb, mongodb

    Summary

    Published
    8 Sept 2026
    UBUNTU-CVE-2026-82054
    No fix available
    Packages

    mongodb, mongodb, mongodb, mongodb

    Summary

    Published
    8 Sept 2026
    UBUNTU-CVE-2026-82053
    No fix available
    Packages

    mongodb, mongodb, mongodb, mongodb

    Summary

    Published
    8 Sept 2026
    CVE-2026-54611
    Fix available
    Packages

    Summary

    InstantCMS has Remote Code Execution in package installer

    Published
    8 Sept 2026
    Packages

    org.thymeleaf.extras:thymeleaf-extras-springsecurity5, org.thymeleaf.extras:thymeleaf-extras-springsecurity6, org.thymeleaf.testing:thymeleaf-testing, org.thymeleaf.testing:thymeleaf-testing-lib, org.thymeleaf.testing:thymeleaf-testing-spring5, org.thymeleaf.testing:thymeleaf-testing-spring6, org.thymeleaf:thymeleaf-lib, org.thymeleaf:thymeleaf-parent, org.thymeleaf:thymeleaf-spring5, org.thymeleaf:thymeleaf-spring6

    Summary

    TuxCare security update for 10 packages (1 CVE)

    Published
    8 Sept 2026
    CVE-2026-86669
    No fix available
    Packages

    Summary

    aircheng-org iWebShop-5 systemseller.php login improper authentication

    Published
    8 Sept 2026
    CVE-2026-72923
    Fix available
    Packages

    Summary

    Microsoft.OpenApi.YamlReader/Readers vulnerable to denial of service via YAML alias expansion

    Published
    8 Sept 2026
    USN-8679-2
    Fix available
    Packages

    vim

    Summary

    vim vulnerability

    Published
    8 Sept 2026
    CGA-cqh5-mfcq-j683
    Fix available
    Packages

    grafana-cloudmonitoring-datasource

    Summary

    Published
    8 Sept 2026
    Packages

    jinja2

    Summary

    TuxCare security update for jinja2 (2 CVEs)

    Published
    8 Sept 2026
    Packages

    scikit-learn

    Summary

    TuxCare security update for scikit-learn (1 CVE)

    Published
    8 Sept 2026
    CVE-2026-86073
    Fix available
    Packages

    Summary

    n8n: Per-Resource OAuth Consent Bypass via Unbound Refresh Token Resource Substitution

    Published
    8 Sept 2026
    USN-8738-1
    Fix available
    Packages

    ffmpeg

    Summary

    ffmpeg vulnerabilities

    Published
    8 Sept 2026
    CVE-2026-82533
    Fix available
    Packages

    Summary

    DeepSeek Harness < 0.1.2-alpha.1 Authentication Bypass via Host Header Spoofing

    Published
    8 Sept 2026
    GHSA-3gq4-3j92-5w49
    Fix available
    Packages

    nltk

    Summary

    NLTK: Corpus Reader Sandbox Bypass

    Published
    8 Sept 2026
    GHSA-p4rw-rvv2-7xwr
    Fix available
    Packages

    nltk

    Summary

    NLTK: Corpus readers follow symlinks outside trusted roots despite pathsec enforcement

    Published
    8 Sept 2026
    Packages

    govulncheck-vulndb

    Summary

    Security update for govulncheck-vulndb

    Published
    8 Sept 2026
    CVE-2026-75156
    Fix available
    Packages

    Summary

    Apache Airflow FAB provider: FAB Azure AD OAuth: id_token issuer/audience not validated — cross-tenant authentication bypass

    Published
    8 Sept 2026
    CGA-7673-6w8c-q6j9
    Fix available
    Packages

    grafana-clickhouse-datasource

    Summary

    Published
    8 Sept 2026
    CVE-2026-86668
    No fix available
    Packages

    Summary

    aircheng-org iWebShop-5 pic.php uploadFile cross site scripting

    Published
    8 Sept 2026
    GHSA-x99w-6fgc-pmfw
    Fix available
    Packages

    nltk

    Summary

    NLTK: Allowlisted pickle loaders still permit code execution in current source

    Published
    8 Sept 2026
    CVE-2026-78216
    Fix available
    Packages

    Summary

    AshLua eval read operations can read field-policy-protected fields via aggregates

    Published
    8 Sept 2026
    EEF-CVE-2026-78216
    Fix available
    Packages

    ash_lua,

    Summary

    AshLua eval read operations can read field-policy-protected fields via aggregates

    Published
    8 Sept 2026
    GHSA-97qj-x29f-37w7
    Fix available
    Packages

    nltk

    Summary

    NLTK: Entity-expansion DoS (billion laughs) via remaining raw ElementTree parses

    Published
    8 Sept 2026
    CVE-2026-78230
    Fix available
    Packages

    Summary

    AshAi aggregate tool can read field-policy-protected fields

    Published
    8 Sept 2026
    EEF-CVE-2026-78230
    Fix available
    Packages

    ash_ai,

    Summary

    AshAi aggregate tool can read field-policy-protected fields

    Published
    8 Sept 2026
    GHSA-6ww7-3frv-cqxh
    Fix available
    Packages

    nltk

    Summary

    NLTK: pathsec SSRF protection can be bypassed when a proxy is configured

    Published
    8 Sept 2026
    GHSA-rhp5-r9x4-f5g2
    Fix available
    Packages

    nltk

    Summary

    NLTK: Unsafe Pickle Deserialization in TransitionParser Allows Remote Code Execution

    Published
    8 Sept 2026
    GHSA-3hhw-38pf-pxj6
    Fix available
    Packages

    nltk

    Summary

    NLTK: Symlink-based arbitrary file read in IPIPANCorpusReader, bypasses nltk.pathsec entirely

    Published
    8 Sept 2026
    GHSA-f833-7jw8-xwrv
    Fix available
    Packages

    nltk

    Summary

    NLTK: Symlink-based sandbox bypass in FramenetCorpusReader (bypasses the fix for CVE-2026-54292)

    Published
    8 Sept 2026
    GHSA-568f-pv23-39p4
    Fix available
    Packages

    nltk

    Summary

    NLTK: Stable FrameNet and NKJP readers parse outside-root XML

    Published
    8 Sept 2026
    SUSE-SU-2026:4093-1
    Fix available
    Packages

    multipath-tools

    Summary

    Security update for multipath-tools

    Published
    8 Sept 2026
    SUSE-SU-2026:4092-1
    Fix available
    Packages

    libzypp, zypper

    Summary

    Security update for libzypp, zypper

    Published
    8 Sept 2026
    CVE-2026-86667
    No fix available
    Packages

    Summary

    aircheng-org iWebShop-5 member.php member_list sql injection

    Published
    8 Sept 2026
    CVE-2026-82076
    Fix available
    Packages

    Summary

    Integer Overflow in Query Planner Leads to Unbounded Memory Allocation and Denial of Service in MongoDB Server

    Published
    8 Sept 2026
    CVE-2026-82075
    Fix available
    Packages

    Summary

    Uncontrolled Resource Consumption in MongoDB Sharded Cluster Router Allows Unauthenticated Denial of Service

    Published
    8 Sept 2026
    CVE-2026-82074
    Fix available
    Packages

    Summary

    Incorrect Authorization in MongoDB Server Aggregation Framework Allows Unauthorized Read Access to Collection Data

    Published
    8 Sept 2026
    CVE-2026-82073
    Fix available
    Packages

    Summary

    Improper Validation in MongoDB Server Aggregation Framework Allows Authorization Bypass and Unauthorized Collection Access with Atlas Search

    Published
    8 Sept 2026
    CVE-2026-82071
    Fix available
    Packages

    Summary

    Insufficient Validation of Storage Engine Configuration Options in MongoDB Server Leads to Out-of-Bounds Write

    Published
    8 Sept 2026
    CVE-2026-82070
    Fix available
    Packages

    Summary

    Insufficiently Protected Credentials in MongoDB Server Diagnostic Reporting Interface

    Published
    8 Sept 2026
    CVE-2026-82069
    Fix available
    Packages

    Summary

    Improper Redaction of Query Literals in MongoDB Server Query Statistics Serialization on Sharded Cluster Router

    Published
    8 Sept 2026
    CVE-2026-82068
    Fix available
    Packages

    Summary

    Persistent Fatal Assertion Crash in MongoDB Server via Crafted Retryable Write Commands Leads to Denial of Service

    Published
    8 Sept 2026