Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
CVE-2026-45698
  • github.com/netatalk/netatalk
Netatalk has Integer Underflow → Stack Buffer Overflow in deletedir() 13 hours ago
  • Fix available
  • Severity - 7.5 (High)
CVE-2026-74238
  • github.com/tier4/nebula
TIER IV Nebula 1.2.0 Heap Out-of-Bounds Read via VLP32 UDP Decoder 14 hours ago
  • No fix available
  • Severity - 8.7 (High)
CVE-2026-73523
  • github.com/covesa/open1722
COVESA Open1722 0.9.2 Stack Memory Disclosure via acf-can-listener.c Integer Truncation 14 hours ago
  • No fix available
  • Severity - 8.7 (High)
CVE-2026-33437
  • github.com/stirling-tools/stirling-pdf
Stirling PDF: Stored XSS in Info Summary 14 hours ago
  • Fix available
  • Severity - 8.1 (High)
CVE-2026-48053
  • github.com/learningequality/kolibri
Kolibri has Unauthenticated Server-Side Request Forgery (SSRF) in RemoteFacilityUserViewset 14 hours ago
  • Fix available
  • Severity - 5.8 (Medium)
CVE-2026-59903
  • github.com/netty/netty
Netty: Cache Poisoning and Information Disclosure via CORS Vary Header Overwrite 14 hours ago
  • Fix available
  • Severity - 6.5 (Medium)
CVE-2026-46345
  • github.com/oscal-compass/compliance-trestle
compliance-trestle - jinja has an Arbitrary File Write via Path Traversal 14 hours ago
  • Fix available
  • Severity - 8.4 (High)
CVE-2026-73522
  • github.com/covesa/open1722
COVESA Open1722 0.9.2 Stack Buffer Overflow via avtp_to_can() in acf-can-listener 14 hours ago
  • No fix available
  • Severity - 8.7 (High)
CVE-2026-71980
  • github.com/belledonnecommunications/bcg729
Belledonne Communications bcg729 1.1.2 Out-of-Bounds Read via decodeSIDframe() 14 hours ago
  • No fix available
  • Severity - 8.7 (High)
CVE-2026-59902
  • github.com/netty/netty
Netty: Memory Exhaustion in SctpMessageCompletionHandler 14 hours ago
  • Fix available
  • Severity - 7.5 (High)
CVE-2026-71979
  • github.com/indilib/indi
INDI indiserver 2.2.4.2 Stack Buffer Overflow via XML Tag Parsing 14 hours ago
  • No fix available
  • Severity - 8.7 (High)
CVE-2026-73424
  • github.com/withastro/astro
Astro: Unauthenticated path override in the @astrojs/vercel ISR function 15 hours ago
  • Fix available
  • Severity - 6.5 (Medium)
CVE-2026-68519
  • github.com/nicolargo/glances
Glances: `--disable-config-exec` does not cover on-alert action commands (incomplete fix of CVE-2026-53925) 15 hours ago
  • Fix available
  • Severity - 7.1 (High)
CVE-2026-62982
  • github.com/nicolargo/glances
Glances: Incomplete fix of CVE-2026-32608: action-template sanitizer is bypassed by nested stat values (process 'cmdline') → OS command injection 15 hours ago
  • Fix available
  • Severity - 8.8 (High)
CVE-2026-68520
  • github.com/nicolargo/glances
Glances: as_dict_secure() Value-Level Bypass Leaks Credentials in URL Values via /api/4/config 15 hours ago
  • Fix available
  • Severity - 5.3 (Medium)
CVE-2026-68517
  • github.com/nicolargo/glances
Glances: REST API CORS Credentials Guard Uses Exact-Match Instead of Membership Test — Bypassed by Any Multi-Origin Allowlist Containing the Wildcard 15 hours ago
  • Fix available
  • Severity - 6.5 (Medium)