Recent
Automated Logout - Moderately critical - Cross-site request forgery - SA-CONTRIB-2026-030
Published 2026-03-26 by drupal
Unpublished Node Permissions - Critical - Access bypass - SA-CONTRIB-2026-029
Published 2026-03-26 by drupal
AI (Artificial Intelligence) - Moderately critical - Information Disclosure - SA-CONTRIB-2026-028
Published 2026-03-26 by drupal
Libssh: libssh: denial of service via improper configuration file handling
Published 2026-03-26 by redhat
Libssh: libssh: denial of service via inefficient regular expression processing
Published 2026-03-26 by redhat
Libssh: libssh: denial of service due to malformed sftp message
Published 2026-03-26 by redhat
Libssh: improper sanitation of paths received from scp servers
Published 2026-03-26 by redhat
Libssh: buffer underflow in ssh_get_hexa() on invalid input
Published 2026-03-26 by redhat
Missing Protected-field Authorization in Provisioning Contact Points API
Published 2026-03-26 by GRAFANA
Grafana MSSQL Data Source Plugin: Restriction Bypass Leading to OOM DoS
Published 2026-03-26 by GRAFANA
Lychee has SSRF bypass via DNS rebinding — PhotoUrlRule only validates IP addresses, not hostnames resolving to internal IPs
Published 2026-03-26 by GitHub_M
OpenID Connect / OAuth client - Less critical - Access bypass - SA-CONTRIB-2026-027
Published 2026-03-26 by drupal
OpenID Connect / OAuth client - Moderately critical - Access bypass - SA-CONTRIB-2026-026
Published 2026-03-26 by drupal
OpenID Connect / OAuth client - Moderately critical - Server-side request forgery, Information disclosure - SA-CONTRIB-2026-025
Published 2026-03-26 by drupal
Google Analytics GA4 - Moderately critical - Cross-site Scripting - SA-CONTRIB-2026-024
Published 2026-03-26 by drupal
Calculation Fields - Moderately critical - Cross-site Scripting - SA-CONTRIB-2026-023
Published 2026-03-26 by drupal
AJAX Dashboard - Critical - Access bypass - SA-CONTRIB-2026-022
Published 2026-03-26 by drupal
File Access Fix (deprecated) - Moderately critical - Access bypass - SA-CONTRIB-2026-021
Published 2026-03-26 by drupal
File Access Fix (deprecated) - Moderately critical - Access bypass - SA-CONTRIB-2026-020
Published 2026-03-26 by drupal
P11-kit: p11-kit: null dereference via c_derivekey with specific null parameters
Published 2026-03-26 by redhat
Lychee has SSRF bypass via incomplete IP validation in Photo::fromUrl — loopback and link-local IPs not blocked
Published 2026-03-26 by GitHub_M
Gimp: gimp: application crash (dos) via crafted psd file due to heap-buffer-overflow
Published 2026-03-26 by redhat
Gimp: gimp: memory corruption due to integer overflow in ico file handling
Published 2026-03-26 by redhat
Gimp: gimp: denial of service via crafted psp image file
Published 2026-03-26 by redhat
ImageMagick has an Out-of-bounds Write via InterpretImageFilename
Published 2026-03-26 by GitHub_M
ImageMagick has an Out-of-Bounds write of a zero byte in its X11 display interaction
Published 2026-03-26 by GitHub_M
yaml is vulnerable to Stack Overflow via deeply nested YAML collections
Published 2026-03-26 by GitHub_M
Infinite loop in github.com/antchfx/xpath
Published 2026-03-26 by Go
Denial of service in github.com/jackc/pgproto3/v2
Published 2026-03-26 by Go
Denial of service in github.com/buger/jsonparser
Published 2026-03-26 by Go
Load more ↓