Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
light_mode
dark_mode
Vulnerabilities
search
All ecosystems
1939396
AlmaLinux
5552
Alpaquita
12738
Alpine
4374
Android
2912
Azure Linux
12016
BellSoft Hardened Containers
616
Bitnami
8541
Chainguard
852567
CleanStart
1988
CRAN
14
crates.io
2630
Debian
62503
Docker Hardened Images
1
Echo
4347
GHC
3
GIT
96593
GitHub Actions
54
Go
8543
Hackage
32
Hex
223
Julia
1644
Linux
26309
Mageia
6104
Maven
6811
MinimOS
105278
npm
226040
NuGet
1830
opam
24
openEuler
7498
openSUSE
13877
OSS-Fuzz
3986
Packagist
6790
Pub
11
PyPI
24326
Red Hat
22016
Rocky Linux
3876
Root
18878
RubyGems
4583
SUSE
22229
SwiftURL
58
TuxCare
8405
Ubuntu
59642
VSCode
20
Wolfi
292914
ID
Packages
Summary
Published
arrow_upward
Attributes
EEF-CVE-2026-67579
Hex/ash
github.com/ash-project/ash
Filter expression injection via forged keyset pagination cursor in Ash
22 hours ago
Fix available
Severity - 7.5 (High)
EEF-CVE-2026-64941
Hex/phoenix_live_view
github.com/phoenixframework/phoenix_live_view
Open redirect in Phoenix.LiveView.validate_local_url!/2 via ASCII tab, LF and CR
3 days ago
Fix available
Severity - 2.1 (Low)
EEF-CVE-2026-70395
Hex/ash
github.com/ash-project/ash
Predicate injection in manage_relationship belongs_to lookup discloses secret lookup keys in Ash
4 days ago
Fix available
Severity - 2.1 (Low)
EEF-CVE-2026-69659
Hex/ash
github.com/ash-project/ash
Memory exhaustion via unbounded deserialization of keyset pagination cursors in Ash.Page.Keyset
4 days ago
Fix available
Severity - 5.9 (Medium)
EEF-CVE-2026-67585
Hex/absinthe_federation
github.com/divvypayhq/absinthe_federation
Atom Exhaustion via _entities Representation Keys in DivvyPayHQ absinthe_federation
6 days ago
Fix available
Severity - 8.7 (High)
EEF-CVE-2026-66838
Hex/postgrex
github.com/elixir-ecto/postgrex
SQL injection via the :comment option in Postgrex.stream/4
6 days ago
Fix available
Severity - 5.9 (Medium)
EEF-CVE-2026-68750
Hex/html_sanitize_ex
github.com/rrrene/html_sanitize_ex
Quadratic sibling re-flattening in the html_sanitize_ex traversal engine allows CPU-exhaustion denial of service
06 Aug
Fix available
Severity - 8.2 (High)
EEF-CVE-2026-68749
Hex/html_sanitize_ex
github.com/rrrene/html_sanitize_ex
Quadratic regex backtracking in the html_sanitize_ex CSS scrubber allows CPU-exhaustion denial of service
06 Aug
Fix available
Severity - 8.2 (High)
EEF-CVE-2026-68747
Hex/html_sanitize_ex
github.com/rrrene/html_sanitize_ex
CSS sanitizer allowlist bypass in html_sanitize_ex via non-declaration input
06 Aug
Fix available
Severity - 2.3 (Low)
EEF-CVE-2026-66829
Hex/html_sanitize_ex
github.com/rrrene/html_sanitize_ex
html_sanitize_ex HTML5 scrubber keeps attacker-supplied meta refresh, allowing forced cross-origin redirection
06 Aug
Fix available
Severity - 2.3 (Low)
EEF-CVE-2026-66370
Hex/html_sanitize_ex
github.com/rrrene/html_sanitize_ex
html_sanitize_ex HTML5 scrubber keeps attacker-supplied form-association attributes, allowing form hijacking
06 Aug
Fix available
Severity - 4.8 (Medium)
EEF-CVE-2026-66843
Hex/html_sanitize_ex
github.com/rrrene/html_sanitize_ex
html_sanitize_ex HTML5 scrubber keeps attacker-supplied `<object>` elements, allowing untrusted content embedding
06 Aug
Fix available
Severity - 2.3 (Low)
EEF-CVE-2026-66885
Hex/livebook
github.com/livebook-dev/livebook
Livebook Teams identity callback lacks state binding, allowing login CSRF
05 Aug
Fix available
Severity - 6.8 (Medium)
EEF-CVE-2026-66298
Hex/livebook
github.com/livebook-dev/livebook
JS-view sandboxed output can synthesize keyboard events to trigger unconfirmed global shortcuts
05 Aug
Fix available
Severity - 8.6 (High)
EEF-CVE-2026-66297
Hex/livebook
github.com/livebook-dev/livebook
Unescaped deployment environment variables in generated setup commands
05 Aug
Fix available
Severity - 5.0 (Medium)
EEF-CVE-2026-66881
Hex/livebook
github.com/livebook-dev/livebook
Path traversal in imported file_entries name allows arbitrary file write via URL-type entry download
05 Aug
Fix available
Severity - 7.0 (High)
Load more...
Hex - OSV