Open Source Vulnerabilities
MISP Event Graph Object Reference Lookup Exposes References from Unauthorized Objects
MISP Event Graph Object Reference Lookup Exposes References from Unauthorized Objects
PocketMine-MP before 3.26.5 and 4.0.5 Input Validation via Book Pages
PocketMine-MP before 3.26.5 and 4.0.5 Input Validation via Book Pages
PocketMine-MP before 3.26.5 and 4.0.5 Denial of Service via Skin Data
PocketMine-MP before 3.26.5 and 4.0.5 Denial of Service via Skin Data
PocketMine-MP 3.x before 3.27.0 Authentication Bypass via Login Replay
PocketMine-MP 3.x before 3.27.0 Authentication Bypass via Login Replay
PocketMine-MP before 4.0.6 Denial of Service via PlayerActionPacket
PocketMine-MP before 4.0.6 Denial of Service via PlayerActionPacket
PocketMine-MP before 4.0.7 Denial of Service via JSON Decoding
PocketMine-MP before 4.0.7 Denial of Service via JSON Decoding
PocketMine-MP before 4.2.3 Denial of Service via NBT Metadata
PocketMine-MP before 4.2.9 Denial of Service via NBT Deserialization
PocketMine-MP before 4.2.9 Denial of Service via NBT Deserialization
PocketMine-MP before 4.2.10 Denial of Service via Chat Messages
PocketMine-MP before 4.2.10 Denial of Service via Chat Messages
PocketMine-MP before 4.4.2 Server Crash via Item ID
commonmark before 2.9.1 XSS via AttributesExtension form feed bypass
commonmark before 2.9.1 XSS via AttributesExtension form feed bypass
league/commonmark before 2.9.1 Denial of Service via parsing
commonmark before 2.9.1 Denial of Service via SmartPunct and Attributes
commonmark before 2.9.1 Denial of Service via SmartPunct and Attributes
commonmark 1.5.0 before 2.10.0 Denial of Service via Attributes
commonmark 1.5.0 before 2.10.0 Denial of Service via Attributes
LibreNMS before 26.8.0 Argument Injection via graph_title
LibreNMS before 26.8.0 Authentication Bypass via API Token Type Confusion
LibreNMS before 26.8.0 Authentication Bypass via API Token Type Confusion
ImageMagick before 7.1.2-30 Heap-use-after-free via Layer
ImageMagick before 7.1.2-30 Path Traversal via TOCTOU Symlink Race
ImageMagick before 7.1.2-30 Path Traversal via TOCTOU Symlink Race
ImageMagick before 7.1.2-30 Heap-use-after-free via GetList
ImageMagick before 7.1.2-30 Path Policy TOCTOU Symlink Race
ImageMagick before 7.1.2-30 Memory Leak via MSL decoder
ImageMagick before 7.1.2-30 Denial of Service Memory Budget
MISP Dashboard Organisation Widgets Bypass Organisation-Index Restrictions and Expose Hidden Organisation Data
MISP Dashboard Organisation Widgets Bypass Organisation-Index Restrictions and Expose Hidden Organisation Data
python3.11, rootio-python3.11
CVE-2025-15367 in python3.11 - Patched by Root
python3.11/ rootio-python3.11
CVE-2025-15367 in python3.11 - Patched by Root
python3.11, rootio-python3.11
CVE-2026-0864 in python3.11 - Patched by Root
python3.11/ rootio-python3.11
CVE-2026-0864 in python3.11 - Patched by Root
python3.11, rootio-python3.11
CVE-2026-11940 in python3.11 - Patched by Root
python3.11/ rootio-python3.11
CVE-2026-11940 in python3.11 - Patched by Root
python3.11, rootio-python3.11
CVE-2026-11972 in python3.11 - Patched by Root
python3.11/ rootio-python3.11
CVE-2026-11972 in python3.11 - Patched by Root
python3.11, rootio-python3.11
CVE-2026-1502 in python3.11 - Patched by Root
python3.11/ rootio-python3.11
CVE-2026-1502 in python3.11 - Patched by Root
python3.11, rootio-python3.11
CVE-2026-3276 in python3.11 - Patched by Root
python3.11/ rootio-python3.11
CVE-2026-3276 in python3.11 - Patched by Root
python3.11, rootio-python3.11
CVE-2026-3446 in python3.11 - Patched by Root
python3.11/ rootio-python3.11
CVE-2026-3446 in python3.11 - Patched by Root
python3.11, rootio-python3.11
CVE-2026-3479 in python3.11 - Patched by Root
python3.11/ rootio-python3.11
CVE-2026-3479 in python3.11 - Patched by Root
python3.11, rootio-python3.11
CVE-2026-4360 in python3.11 - Patched by Root
python3.11/ rootio-python3.11
CVE-2026-4360 in python3.11 - Patched by Root
python3.11, rootio-python3.11
CVE-2025-12781 in python3.11 - Patched by Root
python3.11/ rootio-python3.11
CVE-2025-12781 in python3.11 - Patched by Root
python3.11, rootio-python3.11
CVE-2025-15366 in python3.11 - Patched by Root
python3.11/ rootio-python3.11
CVE-2025-15366 in python3.11 - Patched by Root
python3.11, rootio-python3.11
CVE-2026-6019 in python3.11 - Patched by Root
python3.11/ rootio-python3.11
CVE-2026-6019 in python3.11 - Patched by Root
python3.11, rootio-python3.11
CVE-2026-7774 in python3.11 - Patched by Root
python3.11/ rootio-python3.11
CVE-2026-7774 in python3.11 - Patched by Root
python3.11, rootio-python3.11
CVE-2026-8328 in python3.11 - Patched by Root
python3.11/ rootio-python3.11
CVE-2026-8328 in python3.11 - Patched by Root
MISP Dashboard Button Widget Allows Stored XSS via Unsafe javascript: and Backslash URLs
MISP Dashboard Button Widget Allows Stored XSS via Unsafe javascript: and Backslash URLs
MISP Insufficient Outbound URL Validation Allows SSRF and Credential Disclosure via Feed Redirects and TAXII Discovery
MISP Insufficient Outbound URL Validation Allows SSRF and Credential Disclosure via Feed Redirects and TAXII Discovery
ILIAS before 9.23, 10.11, and 11.4 Missing Authorization in Group Object Action Methods
ILIAS before 9.23, 10.11, and 11.4 Missing Authorization in Group Object Action Methods
MISP Dashboard Organisation Picker Exposes Hidden Organisation Metadata to Unauthorized Users
MISP Dashboard Organisation Picker Exposes Hidden Organisation Metadata to Unauthorized Users
MISP Dashboard Template REST API Exposes Template Owner Email Addresses to Unauthorized Users
MISP Dashboard Template REST API Exposes Template Owner Email Addresses to Unauthorized Users
