Open Source Vulnerabilities
next, @rootio/next
CVE-2026-44573 in next - Patched by Root
next/ @rootio/next
CVE-2026-44573 in next - Patched by Root
next, @rootio/next
CVE-2026-64645 in next - Patched by Root
next/ @rootio/next
CVE-2026-64645 in next - Patched by Root
next, @rootio/next
CVE-2024-46982 in next - Patched by Root
next/ @rootio/next
CVE-2024-46982 in next - Patched by Root
next, @rootio/next
CVE-2024-51479 in next - Patched by Root
next/ @rootio/next
CVE-2024-51479 in next - Patched by Root
next, @rootio/next
CVE-2025-29927 in next - Patched by Root
next/ @rootio/next
CVE-2025-29927 in next - Patched by Root
next, @rootio/next
GHSA-5j59-xgg2-r9c4 in next - Patched by Root
next/ @rootio/next
GHSA-5j59-xgg2-r9c4 in next - Patched by Root
next, @rootio/next
GHSA-q4gf-8mx6-v5v3 in next - Patched by Root
next/ @rootio/next
GHSA-q4gf-8mx6-v5v3 in next - Patched by Root
Concrete CMS 9 through 9.5.2 is vulnerable to Missing Authorization in the orphaned-block alias route, allowing an authenticated editor to disclose and force-delete arbitrary blocks
Concrete CMS 9 through 9.5.2 is vulnerable to Missing Authorization in the orphaned-block alias route, allowing an authenticated editor to disclose and force-delete arbitrary blocks
external-secrets-operator-fips-2.10
external-secrets-operator-fips-2.10
external-secrets-operator-fips-2.10
Concrete CMS 9.5.2 and below is vulnerable to Stored XSS in RSS Displayer Block via Unescaped Remote Feed Item title
Concrete CMS 9.5.2 and below is vulnerable to Stored XSS in RSS Displayer Block via Unescaped Remote Feed Item title
next, @rootio/next
CVE-2026-64641 in next - Patched by Root
next/ @rootio/next
CVE-2026-64641 in next - Patched by Root
next, @rootio/next
GHSA-h25m-26qc-wcjf in next - Patched by Root
next/ @rootio/next
GHSA-h25m-26qc-wcjf in next - Patched by Root
next, @rootio/next
CVE-2024-34351 in next - Patched by Root
next/ @rootio/next
CVE-2024-34351 in next - Patched by Root
next, @rootio/next
GHSA-mwv6-3258-q52c in next - Patched by Root
next/ @rootio/next
GHSA-mwv6-3258-q52c in next - Patched by Root
next, @rootio/next
CVE-2026-44578 in next - Patched by Root
next/ @rootio/next
CVE-2026-44578 in next - Patched by Root
next, @rootio/next
GHSA-8h8q-6873-q5fj in next - Patched by Root
next/ @rootio/next
GHSA-8h8q-6873-q5fj in next - Patched by Root
next, @rootio/next
CVE-2026-64649 in next - Patched by Root
next/ @rootio/next
CVE-2026-64649 in next - Patched by Root
next, @rootio/next
CVE-2024-56332 in next - Patched by Root
next/ @rootio/next
CVE-2024-56332 in next - Patched by Root
glibc
Updated glibc package fixes security vulnerabilities
Concrete CMS 9.2.0 to 9.5.2 Express REST API list endpoint exposes restricted Express entries via Missing Authorization
Concrete CMS 9.2.0 to 9.5.2 Express REST API list endpoint exposes restricted Express entries via Missing Authorization
dompurify
TuxCare security update for dompurify (1 CVE)
Missing Authorization in Concrete CMS 9.2.0 to 9.5.2 REST API Groups List Endpoint Allows Authenticated Users to Enumerate All Groups
Missing Authorization in Concrete CMS 9.2.0 to 9.5.2 REST API Groups List Endpoint Allows Authenticated Users to Enumerate All Groups
dompurify
TuxCare security update for dompurify (1 CVE)
Chamilo LMS Stored XSS via Survey Answer Submission in reporting.php
Chamilo LMS Stored XSS via Survey Answer Submission in reporting.php
org.springframework.ldap:spring-ldap-core
TuxCare security update for org.springframework.ldap:spring-ldap-core (2 CVEs)
org.springframework.ldap:spring-ldap-core
TuxCare security update for org.springframework.ldap:spring-ldap-core (2 CVEs)
next, @rootio/next
CVE-2025-48068 in next - Patched by Root
next/ @rootio/next
CVE-2025-48068 in next - Patched by Root
Denial of service in the event stream header decoder in AWS SDK for Go v2
Denial of service in the event stream header decoder in AWS SDK for Go v2
io.netty:netty-all, io.netty:netty-bom, io.netty:netty-buffer, io.netty:netty-codec, io.netty:netty-codec-dns, io.netty:netty-codec-haproxy, io.netty:netty-codec-http, io.netty:netty-codec-http2, io.netty:netty-codec-memcache, io.netty:netty-codec-mqtt, io.netty:netty-codec-redis, io.netty:netty-codec-smtp, io.netty:netty-codec-socks, io.netty:netty-codec-stomp, io.netty:netty-codec-xml, io.netty:netty-common, io.netty:netty-dev-tools, io.netty:netty-example, io.netty:netty-handler, io.netty:netty-handler-proxy, io.netty:netty-handler-ssl-ocsp, io.netty:netty-microbench, io.netty:netty-parent, io.netty:netty-resolver, io.netty:netty-resolver-dns, io.netty:netty-resolver-dns-classes-macos, io.netty:netty-resolver-dns-native-macos, io.netty:netty-testsuite, io.netty:netty-testsuite-autobahn, io.netty:netty-testsuite-http2, io.netty:netty-testsuite-native, io.netty:netty-testsuite-native-image, io.netty:netty-testsuite-native-image-client, io.netty:netty-testsuite-native-image-client-runtime-init, io.netty:netty-testsuite-osgi, io.netty:netty-testsuite-shading, io.netty:netty-transport, io.netty:netty-transport-blockhound-tests, io.netty:netty-transport-classes-epoll, io.netty:netty-transport-classes-kqueue, io.netty:netty-transport-native-epoll, io.netty:netty-transport-native-kqueue, io.netty:netty-transport-native-unix-common, io.netty:netty-transport-native-unix-common-tests, io.netty:netty-transport-rxtx, io.netty:netty-transport-sctp, io.netty:netty-transport-udt
TuxCare security update for io.netty (1 CVE)
io.netty:netty-all/ io.netty:netty-bom/ io.netty:netty-buffer/ io.netty:netty-codec/ io.netty:netty-codec-dns/ io.netty:netty-codec-haproxy/ io.netty:netty-codec-http/ io.netty:netty-codec-http2/ io.netty:netty-codec-memcache/ io.netty:netty-codec-mqtt/ io.netty:netty-codec-redis/ io.netty:netty-codec-smtp/ io.netty:netty-codec-socks/ io.netty:netty-codec-stomp/ io.netty:netty-codec-xml/ io.netty:netty-common/ io.netty:netty-dev-tools/ io.netty:netty-example/ io.netty:netty-handler/ io.netty:netty-handler-proxy/ io.netty:netty-handler-ssl-ocsp/ io.netty:netty-microbench/ io.netty:netty-parent/ io.netty:netty-resolver/ io.netty:netty-resolver-dns/ io.netty:netty-resolver-dns-classes-macos/ io.netty:netty-resolver-dns-native-macos/ io.netty:netty-testsuite/ io.netty:netty-testsuite-autobahn/ io.netty:netty-testsuite-http2/ io.netty:netty-testsuite-native/ io.netty:netty-testsuite-native-image/ io.netty:netty-testsuite-native-image-client/ io.netty:netty-testsuite-native-image-client-runtime-init/ io.netty:netty-testsuite-osgi/ io.netty:netty-testsuite-shading/ io.netty:netty-transport/ io.netty:netty-transport-blockhound-tests/ io.netty:netty-transport-classes-epoll/ io.netty:netty-transport-classes-kqueue/ io.netty:netty-transport-native-epoll/ io.netty:netty-transport-native-kqueue/ io.netty:netty-transport-native-unix-common/ io.netty:netty-transport-native-unix-common-tests/ io.netty:netty-transport-rxtx/ io.netty:netty-transport-sctp/ io.netty:netty-transport-udt
TuxCare security update for io.netty (1 CVE)
Improper Restriction of XML External Entity References in AWS Advanced JDBC Wrapper RemoteQueryCachePlugin
Improper Restriction of XML External Entity References in AWS Advanced JDBC Wrapper RemoteQueryCachePlugin
