Open Source Vulnerabilities

    Dashboard / Open Source Vulnerabilities

    CGA-wwg4-h25p-jq73
    No fix available
    Packages

    eco-java-gradle-2.12-default

    Summary

    Published
    7 Sept 2026
    CGA-4fh9-x8wh-vwj6
    No fix available
    Packages

    eco-java-gradle-2.12-default

    Summary

    Published
    7 Sept 2026
    CGA-jgwf-rqm8-x7vh
    No fix available
    Packages

    eco-java-gradle-2.12-default

    Summary

    Published
    7 Sept 2026
    CGA-4vhf-42jw-5jm4
    No fix available
    Packages

    eco-java-gradle-2.12-default

    Summary

    Published
    7 Sept 2026
    CGA-q3w6-chp2-fj56
    No fix available
    Packages

    eco-java-gradle-2.12-default

    Summary

    Published
    7 Sept 2026
    CGA-vqx4-9f3r-9vvm
    No fix available
    Packages

    eco-java-gradle-2.12-default

    Summary

    Published
    7 Sept 2026
    CGA-7j8j-3wvw-6356
    No fix available
    Packages

    eco-java-gradle-2.12-default

    Summary

    Published
    7 Sept 2026
    CVE-2026-86451
    Fix available
    Packages

    Summary

    MISP Event Graph Object Reference Lookup Exposes References from Unauthorized Objects

    Published
    7 Sept 2026
    CVE-2022-51018
    Fix available
    Packages

    Summary

    PocketMine-MP before 3.26.5 and 4.0.5 Input Validation via Book Pages

    Published
    7 Sept 2026
    CVE-2022-51017
    Fix available
    Packages

    Summary

    PocketMine-MP before 3.26.5 and 4.0.5 Denial of Service via Skin Data

    Published
    7 Sept 2026
    CVE-2022-51016
    Fix available
    Packages

    Summary

    PocketMine-MP 3.x before 3.27.0 Authentication Bypass via Login Replay

    Published
    7 Sept 2026
    CVE-2022-51015
    Fix available
    Packages

    Summary

    PocketMine-MP before 4.0.6 Denial of Service via PlayerActionPacket

    Published
    7 Sept 2026
    CVE-2022-51014
    Fix available
    Packages

    Summary

    PocketMine-MP before 4.0.7 Denial of Service via JSON Decoding

    Published
    7 Sept 2026
    CVE-2022-51013
    Fix available
    Packages

    Summary

    PocketMine-MP before 4.2.3 Denial of Service via NBT Metadata

    Published
    7 Sept 2026
    CVE-2022-51012
    Fix available
    Packages

    Summary

    PocketMine-MP before 4.2.9 Denial of Service via NBT Deserialization

    Published
    7 Sept 2026
    CVE-2022-51011
    Fix available
    Packages

    Summary

    PocketMine-MP before 4.2.10 Denial of Service via Chat Messages

    Published
    7 Sept 2026
    CVE-2022-51010
    Fix available
    Packages

    Summary

    PocketMine-MP before 4.4.2 Server Crash via Item ID

    Published
    7 Sept 2026
    CVE-2026-86431
    Fix available
    Packages

    Summary

    commonmark before 2.9.1 XSS via AttributesExtension form feed bypass

    Published
    7 Sept 2026
    CVE-2026-86430
    Fix available
    Packages

    Summary

    league/commonmark before 2.9.1 Denial of Service via parsing

    Published
    7 Sept 2026
    CVE-2026-86429
    Fix available
    Packages

    Summary

    commonmark before 2.9.1 Denial of Service via SmartPunct and Attributes

    Published
    7 Sept 2026
    CVE-2026-86428
    Fix available
    Packages

    Summary

    commonmark 1.5.0 before 2.10.0 Denial of Service via Attributes

    Published
    7 Sept 2026
    CVE-2026-86427
    Fix available
    Packages

    Summary

    LibreNMS before 26.8.0 Argument Injection via graph_title

    Published
    7 Sept 2026
    CVE-2026-86426
    Fix available
    Packages

    Summary

    LibreNMS before 26.8.0 Authentication Bypass via API Token Type Confusion

    Published
    7 Sept 2026
    CVE-2026-86425
    Fix available
    Packages

    Summary

    ImageMagick before 7.1.2-30 Heap-use-after-free via Layer

    Published
    7 Sept 2026
    CVE-2026-86424
    Fix available
    Packages

    Summary

    ImageMagick before 7.1.2-30 Path Traversal via TOCTOU Symlink Race

    Published
    7 Sept 2026
    CVE-2026-86423
    Fix available
    Packages

    Summary

    ImageMagick before 7.1.2-30 Heap-use-after-free via GetList

    Published
    7 Sept 2026
    CVE-2026-86422
    Fix available
    Packages

    Summary

    ImageMagick before 7.1.2-30 Path Policy TOCTOU Symlink Race

    Published
    7 Sept 2026
    CVE-2026-86421
    Fix available
    Packages

    Summary

    ImageMagick before 7.1.2-30 Memory Leak via MSL decoder

    Published
    7 Sept 2026
    CVE-2026-86420
    Fix available
    Packages

    Summary

    ImageMagick before 7.1.2-30 Denial of Service Memory Budget

    Published
    7 Sept 2026
    CVE-2026-86441
    Fix available
    Packages

    Summary

    MISP Dashboard Organisation Widgets Bypass Organisation-Index Restrictions and Expose Hidden Organisation Data

    Published
    7 Sept 2026
    Packages

    python3.11, rootio-python3.11

    Summary

    CVE-2025-15367 in python3.11 - Patched by Root

    Published
    7 Sept 2026
    Packages

    python3.11, rootio-python3.11

    Summary

    CVE-2026-0864 in python3.11 - Patched by Root

    Published
    7 Sept 2026
    Packages

    python3.11, rootio-python3.11

    Summary

    CVE-2026-11940 in python3.11 - Patched by Root

    Published
    7 Sept 2026
    Packages

    python3.11, rootio-python3.11

    Summary

    CVE-2026-11972 in python3.11 - Patched by Root

    Published
    7 Sept 2026
    Packages

    python3.11, rootio-python3.11

    Summary

    CVE-2026-1502 in python3.11 - Patched by Root

    Published
    7 Sept 2026
    Packages

    python3.11, rootio-python3.11

    Summary

    CVE-2026-3276 in python3.11 - Patched by Root

    Published
    7 Sept 2026
    Packages

    python3.11, rootio-python3.11

    Summary

    CVE-2026-3446 in python3.11 - Patched by Root

    Published
    7 Sept 2026
    Packages

    python3.11, rootio-python3.11

    Summary

    CVE-2026-3479 in python3.11 - Patched by Root

    Published
    7 Sept 2026
    Packages

    python3.11, rootio-python3.11

    Summary

    CVE-2026-4360 in python3.11 - Patched by Root

    Published
    7 Sept 2026
    Packages

    python3.11, rootio-python3.11

    Summary

    CVE-2025-12781 in python3.11 - Patched by Root

    Published
    7 Sept 2026
    Packages

    python3.11, rootio-python3.11

    Summary

    CVE-2025-15366 in python3.11 - Patched by Root

    Published
    7 Sept 2026
    Packages

    python3.11, rootio-python3.11

    Summary

    CVE-2026-6019 in python3.11 - Patched by Root

    Published
    7 Sept 2026
    Packages

    python3.11, rootio-python3.11

    Summary

    CVE-2026-7774 in python3.11 - Patched by Root

    Published
    7 Sept 2026
    Packages

    python3.11, rootio-python3.11

    Summary

    CVE-2026-8328 in python3.11 - Patched by Root

    Published
    7 Sept 2026
    CVE-2026-86440
    Fix available
    Packages

    Summary

    MISP Dashboard Button Widget Allows Stored XSS via Unsafe javascript: and Backslash URLs

    Published
    7 Sept 2026
    CVE-2026-86419
    Fix available
    Packages

    Summary

    MISP Insufficient Outbound URL Validation Allows SSRF and Credential Disclosure via Feed Redirects and TAXII Discovery

    Published
    7 Sept 2026
    CVE-2026-86416
    Fix available
    Packages

    Summary

    ILIAS before 9.23, 10.11, and 11.4 Missing Authorization in Group Object Action Methods

    Published
    7 Sept 2026
    USN-8733-1
    Fix available
    Packages

    gzip

    Summary

    gzip vulnerabilities

    Published
    7 Sept 2026
    CVE-2026-86418
    Fix available
    Packages

    Summary

    MISP Dashboard Organisation Picker Exposes Hidden Organisation Metadata to Unauthorized Users

    Published
    7 Sept 2026
    CVE-2026-86417
    Fix available
    Packages

    Summary

    MISP Dashboard Template REST API Exposes Template Owner Email Addresses to Unauthorized Users

    Published
    7 Sept 2026