Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
light_mode
dark_mode
Vulnerabilities
search
All ecosystems
2230414
AlmaLinux
5944
Alpaquita
15522
Alpine
4594
Android
2912
Azure Linux
17378
BellSoft Hardened Containers
744
Bitnami
9303
Chainguard
1022897
CleanStart
3529
CRAN
14
crates.io
2730
Debian
68256
Docker Hardened Images
1
Echo
2845
GHC
3
GIT
105228
GitHub Actions
55
Go
9204
Hackage
32
Hex
358
Julia
1713
Linux
28817
Mageia
6224
Maven
7011
MinimOS
143527
npm
228726
NuGet
1867
opam
29
openEuler
8800
openSUSE
14381
OSS-Fuzz
4003
Packagist
7101
Pub
11
PyPI
25149
Red Hat
23316
Rocky Linux
4282
Root
19535
RubyGems
5325
SUSE
23077
SwiftURL
60
TuxCare
9574
Ubuntu
65008
VSCode
21
Wolfi
331308
ID
Packages
Summary
Published
arrow_upward
Attributes
EEF-CVE-2026-92106
Hex/lazy_html
github.com/dashbitco/lazy_html
lazy_html serializes SVG and MathML style and script text unescaped, allowing mutation XSS
8 hours ago
Fix available
Severity - 2.3 (Low)
EEF-CVE-2026-93477
Hex/ash
github.com/ash-project/ash
Private action arguments can be set by user input on the bulk destroy and bulk update paths in Ash
10 hours ago
Fix available
Severity - 5.9 (Medium)
CVE-2026-97724
github.com/software-mansion/react-native-reanimated
See record for full details
15 hours ago
Fix available
Severity - 5.3 (Medium)
CVE-2026-53493
github.com/containerd/containerd
Containerd has image-pull DoS via crafted OCI index graph amplification
17 hours ago
No fix available
Severity - 6.9 (Medium)
CVE-2026-97636
github.com/apache/airflow
Apache Airflow HashiCorp provider: HashiCorp Vault secrets backend: team-scope guard bypass via user-controlled key
19 hours ago
Fix available
CVE-2026-93353
github.com/9001/copyparty
copyparty SFTP Volume Restriction Bypass via mkdir/rmdir/chattr Handlers
21 hours ago
No fix available
Severity - 6.0 (Medium)
CVE-2026-48543
github.com/krayin/laravel-crm
Krayin CRM 2.2.6 Stored Template Injection XSS via Web Form Description
22 hours ago
No fix available
Severity - 5.1 (Medium)
CVE-2026-48542
github.com/krayin/laravel-crm
Krayin CRM 2.2.6 Stored Template Injection XSS via Product Name Field
22 hours ago
No fix available
Severity - 5.1 (Medium)
CVE-2026-48541
github.com/krayin/laravel-crm
Krayin CRM 2.2.6 Stored Template Injection XSS via Contact Name Field
22 hours ago
No fix available
Severity - 5.1 (Medium)
CVE-2026-48540
github.com/krayin/laravel-crm
Krayin CRM 2.2.6 Stored Template Injection XSS via Lead Title
22 hours ago
No fix available
Severity - 5.1 (Medium)
CVE-2026-96883
github.com/aws/pgcollection
Type confusion in AWS pgcollection allows remote code execution
22 hours ago
No fix available
Severity - 8.7 (High)
CVE-2026-57440
github.com/starcitizenwiki/mediawiki-extensions-embedvideo
Mediawiki EmbedVideo Extension has stored XSS via malformed src url with $wgEmbedVideoRequireConsent disabled
23 hours ago
Fix available
Severity - 7.5 (High)
CVE-2026-48073
github.com/docmost/docmost
Docmost: Page export can include restricted same-space attachments through forged attachmentId
23 hours ago
Fix available
Severity - 4.3 (Medium)
CVE-2026-52853
github.com/docmost/docmost
Docmost: Privilege Escalation - ADMIN Can Invite Users as OWNER
23 hours ago
Fix available
Severity - 5.2 (Medium)
CVE-2026-61823
github.com/code16/sharp
code16 Sharp vulnerable to stored XSS via iframe srcdoc Attribute
23 hours ago
Fix available
Severity - 7.3 (High)
CVE-2026-48072
github.com/docmost/docmost
Docmost: Public image fileName path traversal leads to unauthorized local file read
23 hours ago
Fix available
Severity - 5.3 (Medium)
Load more...
GIT - OSV