MEDIUM5.3CVE-2026-49342YARD is a documentation generation tool for the Ruby programming language.
MEDIUM4.3libde265 is an open source implementation of the h.265 video codec.
MEDIUM6.5A use-after-free vulnerability was found in FFmpeg's RASC video decoder.
MEDIUM4.4Outerbase Studio: Stored XSS in Text Widget Leads to Authentication Token Exposure
MEDIUM6.1Allure Report: Stored XSS via unescaped ANSI helper in status message/trace rendering
MEDIUM6.2Allure Report: Path Traversal in HTTP Server Allows Arbitrary File Read
MEDIUM6.5libheif is a HEIF and AVIF file format decoder and encoder.
MEDIUM5.8guzzlehttp/guzzle: Dot-Only Cookie Domains Match All Hosts
MEDIUM5.9guzzlehttp/guzzle: Silent HTTPS-Proxy Downgrade to Cleartext
MEDIUM5.3NL Portal Backend Libraries: Unauthenticated form resolver forwards the privileged Objecten-API token to a caller-supplied URL (SSRF)
HIGH8.3libssh2 through 1.11.1, fixed in commit 2dae302, contains an out-of-bounds heap read vulnerability in the sftp_symlink() function in src/sf…
CRITICAL9.9Network-AI: Improper Neutralization of Special Elements used in an OS Command
CRITICAL9.1Network-AI: CVE-2026-46701 fix incomplete — empty default secret still authorizes all requests
MEDIUM6.5A path traversal in handling the "path" component of .repo files processed by libzypp before 17.38.13 in the 17.x series, or before 16.22.1…
MEDIUM6.1OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry.
MEDIUM5.4Coturn is a free open source implementation of TURN and STUN Server.
MEDIUM4.9libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_ResumeParser from within handlers in cases of a policy violation.
MEDIUM4.8guzzlehttp/psr7: CRLF Injection in HTTP Start-Line Serialization
MEDIUM5.3ts-deepmerge: Prototype Method Override leads to DoS
CRITICAL9.0HAProxy through 3.4.0, fixed in commit 5985276, contains an integer overflow vulnerability in the fcgi_conn structure's drl field that allo…
MEDIUM5.3A flaw in Node.js HTTP/2 server API can cause servers to keep accepting data even after sending a `GOAWAY` frame.
MEDIUM6.7NILFS utilities through 2.3.0, fixed in commit 26efb5d, nilfs_sb_is_valid() function fails to validate s_log_block_size field in NILFS2 sup…
MEDIUM5.8Signal K Server: Server-Side Request Forgery via Remote Connection Endpoints
CRITICAL9.8gemini-mcp-tool vulnerable to OS command injection and @file exfiltration via prompt quoting (CVE-2026-0755)
MEDIUM5.4OpenClaw: Empty-scope device re-pairing could confuse caller scope containment