Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
light_mode
dark_mode
Vulnerabilities
search
All ecosystems
1932362
AlmaLinux
5498
Alpaquita
12401
Alpine
4355
Android
2912
Azure Linux
12016
BellSoft Hardened Containers
612
Bitnami
8541
Chainguard
851240
CleanStart
1988
CRAN
14
crates.io
2603
Debian
61938
Docker Hardened Images
1
Echo
4306
GHC
3
GIT
95684
GitHub Actions
54
Go
8523
Hackage
32
Hex
219
Julia
1548
Linux
26003
Mageia
6096
Maven
6783
MinimOS
103609
npm
225743
NuGet
1818
opam
24
openEuler
7498
openSUSE
13830
OSS-Fuzz
3983
Packagist
6774
Pub
11
PyPI
24265
Red Hat
21891
Rocky Linux
3842
Root
18789
RubyGems
4583
SUSE
22121
SwiftURL
58
TuxCare
8256
Ubuntu
59211
VSCode
20
Wolfi
292666
ID
Packages
Summary
Published
arrow_upward
Attributes
CVE-2026-52880
github.com/klever-io/klever-go
Klever-Go: REST API slow-header connection exhaustion via Gin Engine.Run
23 hours ago
Fix available
Severity - 7.5 (High)
CVE-2026-47127
github.com/ghostfolio/ghostfolio
Ghostfolio has a Stripe subscription bypass
23 hours ago
Fix available
Severity - 6.5 (Medium)
CVE-2026-48122
github.com/shopify/ruby-lsp
Workspace settings can override executable and Gemfile paths used by the Ruby LSP VS Code extension
23 hours ago
Fix available
Severity - 5.4 (Medium)
CVE-2026-52879
github.com/klever-io/klever-go
Klever-Go: Unbounded goroutine spawn on direct-message ingress enables peer-driven DoS
23 hours ago
Fix available
Severity - 7.5 (High)
CVE-2026-48120
github.com/mawww/kakoune
Kakoune has a Critical RCE via Autorestore Backup Filename Injection
23 hours ago
Fix available
Severity - 8.6 (High)
CVE-2026-52878
github.com/klever-io/klever-go
Klever-Go: Unauthenticated nil-pointer DoS in P2P transaction validation can halt the chain
23 hours ago
Fix available
Severity - 7.5 (High)
CVE-2026-48026
github.com/treeverse/lakefs
lakeFS vulnerable to stored XSS in rendered markdown previews via raw HTML
23 hours ago
Fix available
Severity - 8.7 (High)
CVE-2026-49343
github.com/klever-io/klever-go
Klever-Go KVM: Throttler slot leak in trie account-data sync causes epoch bootstrap / state sync DoS
yesterday
Fix available
Severity - 5.9 (Medium)
CVE-2026-46409
github.com/openyak/openyak
OpenYak local API: unauthenticated CSRF chain leads to Remote Code Execution
yesterday
Fix available
Severity - 9.6 (Critical)
CVE-2026-48047
github.com/xwiki/xwiki-platform
XWiki Platform vulnerable to potential arbitrary file writing using path traversal from (subwiki) admin
yesterday
Fix available
Severity - 5.9 (Medium)
CVE-2026-47249
github.com/klever-io/klever-go
Klever-Go KVM: Hash-array amplification in P2P resolver request handling
yesterday
Fix available
Severity - 7.5 (High)
CVE-2026-58262
github.com/klever-io/klever-go
Klever-Go: PubKeysBitmap padding bits bypass the BLS signature quorum
yesterday
Fix available
Severity - 7.1 (High)
CVE-2026-64676
github.com/kata-containers/kata-containers
Kata Containers: Unauthorized mem-agent ttRPC methods let an untrusted host tamper with confidential-guest memory
yesterday
Fix available
Severity - 5.7 (Medium)
CVE-2026-47243
github.com/kata-containers/kata-containers
Kata guest escape: runtime-rs guest-root to host-root escape via virtiofs
yesterday
Fix available
Severity - 9.2 (Critical)
CVE-2026-48170
github.com/thomaspoignant/scim-patch
scimPatch vulnerable to prototype pollution via unfiltered keys in patch
yesterday
Fix available
Severity - 9.1 (Critical)
CVE-2026-45808
github.com/openbao/openbao
OpenBao's cross-namespace lease revocation via legacy sys/revoke path bypasses ACL
yesterday
Fix available
Severity - 7.1 (High)
Load more...
GIT - OSV