Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
light_mode
dark_mode
Vulnerabilities
search
All ecosystems
2308995
AlmaLinux
6003
Alpaquita
16176
Alpine
4655
Android
2912
Azure Linux
17971
BellSoft Hardened Containers
770
Bitnami
9517
Chainguard
1048512
CleanStart
5432
CRAN
14
crates.io
2768
Debian
68982
Docker Hardened Images
1
Echo
4008
GHC
3
GIT
107838
GitHub Actions
55
Go
9334
Hackage
33
Hex
365
Julia
1713
Linux
29270
Mageia
6237
Maven
7055
MinimOS
148516
npm
229266
NuGet
1869
opam
29
openEuler
8900
openSUSE
14651
OSS-Fuzz
4003
Packagist
7109
Pub
11
PyPI
25490
Red Hat
23535
Rocky Linux
4344
Root
19644
RubyGems
5369
SUSE
23454
SwiftURL
61
TuxCare
9676
Ubuntu
66099
VSCode
21
Wolfi
337011
WordPress
30313
ID
Packages
Summary
Published
arrow_upward
Attributes
EEF-CVE-2026-94201
Hex/ash
github.com/ash-project/ash
Filtering an :atom attribute with unsafe_to_atom? can exhaust the BEAM atom table in Ash
7 hours ago
Fix available
Severity - 8.2 (High)
CVE-2026-105641
github.com/makeplane/plane
Plane: Hardcoded SECRET_KEY and LIVE_SERVER_SECRET_KEY shipped in aio/cli...
9 hours ago
Fix available
Severity - 9.8 (Critical)
CVE-2026-105640
github.com/makeplane/plane
Plane: Account Takeover via Unverified OAuth Email Match (Gitea, self-managed...
9 hours ago
Fix available
Severity - 9.1 (Critical)
CVE-2026-105639
github.com/makeplane/plane
Plane: Pre-auth workspace invitation hijack via email-squat and self-served...
9 hours ago
Fix available
Severity - 9.8 (Critical)
CVE-2026-105638
github.com/makeplane/plane
Plane: Magic-code verifier endpoint has no rate limit, enabling 6-digit OTP...
9 hours ago
Fix available
Severity - 9.1 (Critical)
CVE-2026-105637
github.com/makeplane/plane
Plane: Cross-Project Asset Hijacking via 'ProjectBulkAssetEndpoint' (sibling of...
9 hours ago
Fix available
Severity - 9.6 (Critical)
CVE-2026-105636
github.com/makeplane/plane
Plane: SSRF via HTTP redirect in webhook delivery (allow_redirects not set)
9 hours ago
Fix available
Severity - 9.9 (Critical)
CVE-2026-105635
github.com/makeplane/plane
Plane: Unauthenticated Project Invitation Email Disclosure Enables Unauthorized...
9 hours ago
Fix available
Severity - 7.4 (High)
CVE-2026-105634
github.com/makeplane/plane
Plane: Privilege Escalation: Project Guest Can Demote Admin/Member Roles
9 hours ago
Fix available
Severity - 8.1 (High)
CVE-2026-105633
github.com/makeplane/plane
Plane: Issue Attachment Ownership Hijacking via Missing `issue_id` Scope
9 hours ago
Fix available
Severity - 7.1 (High)
CVE-2026-105632
github.com/makeplane/plane
Plane: Broken Access Control - joinProject GraphQL mutation allows self-join...
9 hours ago
Fix available
Severity - 8.7 (High)
CVE-2026-93323
github.com/moby/buildkit
Oversized Dockerfile or .dockerignore can exhaust buildkitd memory
9 hours ago
No fix available
Severity - 6.8 (Medium)
CVE-2026-105631
github.com/makeplane/plane
Plane: asset download endpoints scope file lookups to the workspace (not the...
9 hours ago
Fix available
Severity - 7.5 (High)
CVE-2026-105630
github.com/makeplane/plane
Plane: Stored XSS via SVG attachment served inline on the application origin...
9 hours ago
Fix available
Severity - 8.7 (High)
CVE-2026-93322
github.com/moby/buildkit
Malformed MergeOp can crash the BuildKit daemon
9 hours ago
No fix available
Severity - 6.9 (Medium)
CVE-2026-105629
github.com/makeplane/plane
Plane: Cross-Tenant Destructive IDOR: Estimate Point Deletion via Unscoped...
9 hours ago
Fix available
Severity - 7.1 (High)
Load more...
GIT - OSV