Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
DEBIAN-CVE-2026-19872
  • Debian:12/libhtml-formhandler-perl
  • Debian:13/libhtml-formhandler-perl
  • Debian:14/libhtml-formhandler-perl
See record for full details 17 minutes ago
  • No fix available
DEBIAN-CVE-2026-85484
  • Debian:12/libhtml-formhandler-perl
  • Debian:13/libhtml-formhandler-perl
  • Debian:14/libhtml-formhandler-perl
See record for full details 17 minutes ago
  • No fix available
DEBIAN-CVE-2026-85485
  • Debian:12/libhtml-formhandler-perl
  • Debian:13/libhtml-formhandler-perl
  • Debian:14/libhtml-formhandler-perl
See record for full details 17 minutes ago
  • No fix available
DEBIAN-CVE-2026-85630
  • Debian:12/libhtml-formhandler-perl
  • Debian:13/libhtml-formhandler-perl
  • Debian:14/libhtml-formhandler-perl
See record for full details 17 minutes ago
  • No fix available
GHSA-7hgx-277f-7vmg
  • npm/n8n
n8n: Agent Workflow Tool Bypasses Sub-Workflow Caller Policy 31 minutes ago
  • Fix available
  • Severity - 5.3 (Medium)
GHSA-wmmp-3585-3rmp
  • npm/nodemailer
Nodemailer: IDN/Punycode domain allow-list bypass leads to email delivery to an attacker-controlled domain 31 minutes ago
  • Fix available
  • Severity - 6.5 (Medium)
GHSA-2x7j-588g-ccc2
  • npm/nodemailer
Nodemailer: Quadratic (O(n²)) time complexity in addressparser allows remote denial of service via a crafted address list 31 minutes ago
  • Fix available
  • Severity - 7.5 (High)
GHSA-cc9r-2j5m-2m83
  • npm/nodemailer
Nodemailer: Recipient-domain validation bypass via RFC 5322 comment mis-parsing leads to email delivery to an attacker-controlled domain 31 minutes ago
  • Fix available
  • Severity - 6.5 (Medium)
GHSA-2q42-4q24-7rgv
  • npm/@typespec/compiler
  • npm/@typespec/openapi3
OpenAPI3 version value escapes `emitterOutputDir` and overwrites YAML/JSON outside the output tree 33 minutes ago
  • No fix available
  • Severity - 7.1 (High)
GHSA-wc9g-mqfw-jrwm
  • npm/multer
multer vulnerable to Denial of Service via crafted multipart field names 34 minutes ago
  • Fix available
  • Severity - 7.5 (High)
GHSA-qfvm-cv95-jqjf
  • npm/multer
multer vulnerable to Denial of Service via file descriptor leak on aborted uploads 34 minutes ago
  • Fix available
  • Severity - 7.5 (High)
GHSA-qvfw-j98x-7q72
  • npm/multer
multer vulnerable to file size limit bypass via async fileFilter race condition 35 minutes ago
  • Fix available
  • Severity - 3.7 (Low)
GHSA-535w-7cp7-47q4
  • npm/multer
multer vulnerable to Denial of Service via oversized array index in field names 36 minutes ago
  • Fix available
  • Severity - 7.5 (High)
GHSA-jxfw-x594-9x9m
  • npm/morgan
morgan vulnerable to Log Forging via unescaped Unicode line separators 36 minutes ago
  • Fix available
  • Severity - 5.3 (Medium)
GHSA-96p9-rh4f-92cf
  • PyPI/winml-cli
Windows ML CLI: CORS misconfig enables localhost RCE 36 minutes ago
  • Fix available
  • Severity - 8.6 (High)
GHSA-65fr-j4p9-vc33
  • Packagist/mongodb/mongodb
mongodb: Reject "." and NUL bytes in database and collection names 37 minutes ago
  • Fix available
  • Severity - 8.6 (High)