Filter and search through 392,104 vulnerabilities
| CVE ID | Description | CVSS | Priority | Trend | Exploit | Patch |
|---|---|---|---|---|---|---|
| CVE-2026-24006 | Serialization of objects with extreme depth can **exceed the maximum call stack limit**. **Mitigation**: `Seroval` introduces a `depthLimit` para... | 7.5 | 386 | Neutral | No |
| Yes |
| CVE-2026-24002 | Grist is spreadsheet software using Python as its formula language. Grist offers several methods for running those formulas in a sandbox, for cases wh... | 9.0 | 571 | Neutral | No | No |
| CVE-2026-24001 | ### Impact Attempting to parse a patch whose filename headers contain the line break characters `\r`, `\u2028`, or `\u2029` can cause the `parsePatch... | 0.0 | 0 | Neutral | No | Yes |
| CVE-2026-23996 | ### Impact Timing side-channel vulnerability in verify_key(). The method applied a random delay only on verification failures, allowing an attacker to... | 3.7 | 102 | Neutral | No | Yes |
| CVE-2026-23992 | # Security Disclosure: Improper validation of configured threshold for delegations ## Summary A compromised or misconfigured TUF repository can have... | 5.9 | 155 | Neutral | No | Yes |
| CVE-2026-23991 | # Security Disclosure: Client DoS via malformed server response ## Summary If the TUF repository (or any of its mirrors) returns invalid TUF metadat... | 5.9 | 155 | Neutral | No | Yes |
| CVE-2026-23990 | A privilege escalation vulnerability exists in the Flux Operator Web UI authentication code that allows an attacker to bypass Kubernetes RBAC imperson... | 5.3 | 182 | Neutral | No | Yes |
| CVE-2026-23988 | Rufus is a utility that helps format and create bootable USB flash drives. Versions 4.11 and below contain a race condition (TOCTOU) in src/net.c duri... | 7.3 | 343 | Neutral | No | No |
| CVE-2026-23986 | ### Impact Copier suggests that it's safe to generate a project from a safe template, i.e. one that doesn't use [unsafe](https://copier.readthedocs.i... | 0.0 | 0 | Neutral | No | Yes |
| CVE-2026-23978 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Softwebmedia Gyan Elements gy... | 0.0 | 0 | Neutral | No | Yes |
| CVE-2026-23976 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Chill Modula Image Gallery modula-best-grid-g... | 0.0 | 0 | Neutral | No | Yes |
| CVE-2026-23975 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in uxper Golo golo allows PHP Lo... | 0.0 | 0 | Neutral | No | Yes |
| CVE-2026-23974 | Missing Authorization vulnerability in uxper Golo golo allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Golo... | 0.0 | 0 | Neutral | No | Yes |
| CVE-2026-23968 | ### Impact Copier suggests that it's safe to generate a project from a safe template, i.e. one that doesn't use [unsafe](https://copier.readthedocs.i... | 0.0 | 0 | Neutral | No | Yes |
| CVE-2026-23967 | ### Summary A signature malleability vulnerability exists in the SM2 signature verification logic of the sm-crypto library. An attacker can derive a ... | 7.5 | 386 | Neutral | No | Yes |
| CVE-2026-23966 | ### Summary A private key recovery vulnerability exists in the SM2 decryption logic of sm-crypto. By interacting with the SM2 decryption interface mu... | 9.1 | 568 | Neutral | No | Yes |
| CVE-2026-23965 | ### Summary A signature forgery vulnerability exists in the SM2 signature verification logic of sm-crypto. Under default configurations, an attacker ... | 7.5 | 386 | Neutral | No | Yes |
| CVE-2026-23964 | Mastodon is a free, open-source social network server based on ActivityPub. Prior to versions 4.5.5, 4.4.12, and 4.3.18, an insecure direct object ref... | 6.5 | 224 | Neutral | No | No |
| CVE-2026-23963 | Mastodon is a free, open-source social network server based on ActivityPub. Prior to versions 4.5.5, 4.4.12, and 4.3.18, the server does not enforce a... | 4.3 | 107 | Neutral | No | No |
| CVE-2026-23962 | Mastodon is a free, open-source social network server based on ActivityPub. Mastodon versions before v4.3.18, v4.4.12, and v4.5.5 do not have a limit ... | 7.5 | 394 | Neutral | No | No |