Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
EEF-CVE-2026-92106
  • Hex/lazy_html
  • github.com/dashbitco/lazy_html
lazy_html serializes SVG and MathML style and script text unescaped, allowing mutation XSS 8 hours ago
  • Fix available
  • Severity - 2.3 (Low)
EEF-CVE-2026-93477
  • Hex/ash
  • github.com/ash-project/ash
Private action arguments can be set by user input on the bulk destroy and bulk update paths in Ash 10 hours ago
  • Fix available
  • Severity - 5.9 (Medium)
CVE-2026-97724
  • github.com/software-mansion/react-native-reanimated
See record for full details 15 hours ago
  • Fix available
  • Severity - 5.3 (Medium)
CVE-2026-53493
  • github.com/containerd/containerd
Containerd has image-pull DoS via crafted OCI index graph amplification 17 hours ago
  • No fix available
  • Severity - 6.9 (Medium)
CVE-2026-97636
  • github.com/apache/airflow
Apache Airflow HashiCorp provider: HashiCorp Vault secrets backend: team-scope guard bypass via user-controlled key 19 hours ago
  • Fix available
CVE-2026-93353
  • github.com/9001/copyparty
copyparty SFTP Volume Restriction Bypass via mkdir/rmdir/chattr Handlers 21 hours ago
  • No fix available
  • Severity - 6.0 (Medium)
CVE-2026-48543
  • github.com/krayin/laravel-crm
Krayin CRM 2.2.6 Stored Template Injection XSS via Web Form Description 22 hours ago
  • No fix available
  • Severity - 5.1 (Medium)
CVE-2026-48542
  • github.com/krayin/laravel-crm
Krayin CRM 2.2.6 Stored Template Injection XSS via Product Name Field 22 hours ago
  • No fix available
  • Severity - 5.1 (Medium)
CVE-2026-48541
  • github.com/krayin/laravel-crm
Krayin CRM 2.2.6 Stored Template Injection XSS via Contact Name Field 22 hours ago
  • No fix available
  • Severity - 5.1 (Medium)
CVE-2026-48540
  • github.com/krayin/laravel-crm
Krayin CRM 2.2.6 Stored Template Injection XSS via Lead Title 22 hours ago
  • No fix available
  • Severity - 5.1 (Medium)
CVE-2026-96883
  • github.com/aws/pgcollection
Type confusion in AWS pgcollection allows remote code execution 22 hours ago
  • No fix available
  • Severity - 8.7 (High)
CVE-2026-57440
  • github.com/starcitizenwiki/mediawiki-extensions-embedvideo
Mediawiki EmbedVideo Extension has stored XSS via malformed src url with $wgEmbedVideoRequireConsent disabled 23 hours ago
  • Fix available
  • Severity - 7.5 (High)
CVE-2026-48073
  • github.com/docmost/docmost
Docmost: Page export can include restricted same-space attachments through forged attachmentId 23 hours ago
  • Fix available
  • Severity - 4.3 (Medium)
CVE-2026-52853
  • github.com/docmost/docmost
Docmost: Privilege Escalation - ADMIN Can Invite Users as OWNER 23 hours ago
  • Fix available
  • Severity - 5.2 (Medium)
CVE-2026-61823
  • github.com/code16/sharp
code16 Sharp vulnerable to stored XSS via iframe srcdoc Attribute 23 hours ago
  • Fix available
  • Severity - 7.3 (High)
CVE-2026-48072
  • github.com/docmost/docmost
Docmost: Public image fileName path traversal leads to unauthorized local file read 23 hours ago
  • Fix available
  • Severity - 5.3 (Medium)