Published issues
CGI::Session::ID::md5 versions before 4.49 for Perl generate predictable session ids from low-entropy sources
Permalink
CVE-2026-56016
5.9 MEDIUM
-
CVSS version (CVSS): 3.1
-
Attack Vector (AV): Network (N)
-
Attack Complexity (AC): High (H)
-
Privileges Required (PR): None (N)
-
User Interaction (UI): None (N)
-
Scope (S): Unchanged (U)
-
Confidentiality (C): High (H)
-
Integrity (I): None (N)
-
Availability (A): None (N)
-
Modified Attack Vector (MAV): Network (N)
-
Modified Attack Complexity (MAC): High (H)
-
Modified Privileges Required (MPR): None (N)
-
Modified User Interaction (MUI): None (N)
-
Modified Confidentiality (MC): High (H)
-
Modified Scope (MS): Unchanged (U)
-
Modified Integrity (MI): None (N)
-
Modified Availability (MA): None (N)
updated
3 weeks, 5 days ago
by @LeSuisse
Activity log
-
Created suggestion
3 weeks, 6 days ago
-
@LeSuisse
accepted
3 weeks, 5 days ago
-
@LeSuisse
published on GitHub
3 weeks, 5 days ago
CGI::Session::ID::md5 versions before 4.49 for Perl generate predictable session ids from low-entropy sources
Mass Assignment via Onboarding Endpoint Allows Unauthenticated JWT_SECRET Overwrite
Permalink
CVE-2026-50160
10.0 CRITICAL
-
CVSS version (CVSS): 3.1
-
Attack Vector (AV): Network (N)
-
Attack Complexity (AC): Low (L)
-
Privileges Required (PR): None (N)
-
User Interaction (UI): None (N)
-
Scope (S): Changed (C)
-
Confidentiality (C): High (H)
-
Integrity (I): High (H)
-
Availability (A): None (N)
-
Modified Attack Vector (MAV): Network (N)
-
Modified Attack Complexity (MAC): Low (L)
-
Modified Privileges Required (MPR): None (N)
-
Modified User Interaction (MUI): None (N)
-
Modified Confidentiality (MC): High (H)
-
Modified Scope (MS): Changed (C)
-
Modified Integrity (MI): High (H)
-
Modified Availability (MA): None (N)
updated
3 weeks, 5 days ago
by @LeSuisse
Activity log
-
Created suggestion
3 weeks, 6 days ago
-
@LeSuisse
accepted
3 weeks, 5 days ago
-
@LeSuisse
published on GitHub
3 weeks, 5 days ago
Mass Assignment via Onboarding Endpoint Allows Unauthenticated JWT_SECRET Overwrite
Gradio < 6.16.0 Path Traversal via FileExplorer.preprocess()
Permalink
CVE-2026-49119
8.7 HIGH
-
CVSS version (CVSS): 4.0
-
Attack Vector (AV): Network (N)
-
Attack Complexity (AC): Low (L)
-
Attack Requirement (AT): None (N)
-
Privileges Required (PR): None (N)
-
User Interaction (UI): None (N)
-
Vulnerable System Impact Confidentiality (VC): High (H)
-
Vulnerable System Impact Integrity (VI): None (N)
-
Vulnerable System Impact Availability (VA): None (N)
-
Subsequent System Impact Confidentiality (SC): None (N)
-
Subsequent System Impact Integrity (SI): None (N)
-
Subsequent System Impact Availability (SA): None (N)
-
Modified Attack Vector (MAV): Network (N)
-
Modified Attack Complexity (MAC): Low (L)
-
Modified Attack Requirement (MAT): None (N)
-
Modified Privileges Required (MPR): None (N)
-
Modified User Interaction (MUI): None (N)
-
Modified Vulnerable System Impact Confidentiality (MVC): High (H)
-
Modified Vulnerable System Impact Integrity (MVI): None (N)
-
Modified Vulnerable System Impact Availability (MVA): None (N)
-
Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
-
Modified Subsequent System Impact Integrity (MSI): Negligible (N)
-
Modified Subsequent System Impact Availability (MSA): Negligible (N)
-
Safety (S): Not Defined (X)
-
Automatable (AU): Not Defined (X)
-
Recovery (R): Not Defined (X)
-
Value Density (V): Not Defined (X)
-
Vulnerability Response Effort (RE): Not Defined (X)
-
Provider Urgency (U): Not Defined (X)
-
Confidentiality Req. (CR): Not Defined (X)
-
Integrity Req. (IR): Not Defined (X)
-
Availability Req. (AR): Not Defined (X)
-
Exploit Maturity (E): Not Defined (X)
updated
3 weeks, 5 days ago
by @LeSuisse
Activity log
-
Created suggestion
3 weeks, 6 days ago
-
@LeSuisse
ignored
8 packages
- python312Packages.gradio-pdf
- python313Packages.gradio-pdf
- python314Packages.gradio-pdf
- python312Packages.gradio-client
- python313Packages.gradio-client
- python314Packages.gradio-client
- pkgsRocm.python3Packages.gradio-pdf
- pkgsRocm.python3Packages.gradio-client
3 weeks, 5 days ago
-
@LeSuisse
accepted
3 weeks, 5 days ago
-
@LeSuisse
published on GitHub
3 weeks, 5 days ago
Gradio < 6.16.0 Path Traversal via FileExplorer.preprocess()
runc: Malicious image with /dev symlink can trigger limited host filesystem integrity violations
Permalink
CVE-2026-41579
3.3 LOW
-
CVSS version (CVSS): 3.1
-
Attack Vector (AV): Local (L)
-
Attack Complexity (AC): Low (L)
-
Privileges Required (PR): None (N)
-
User Interaction (UI): Required (R)
-
Scope (S): Unchanged (U)
-
Confidentiality (C): None (N)
-
Integrity (I): Low (L)
-
Availability (A): None (N)
-
Modified Attack Vector (MAV): Local (L)
-
Modified Attack Complexity (MAC): Low (L)
-
Modified Privileges Required (MPR): None (N)
-
Modified User Interaction (MUI): Required (R)
-
Modified Confidentiality (MC): None (N)
-
Modified Scope (MS): Unchanged (U)
-
Modified Integrity (MI): Low (L)
-
Modified Availability (MA): None (N)
updated
3 weeks, 5 days ago
by @LeSuisse
Activity log
-
Created suggestion
3 weeks, 6 days ago
-
@LeSuisse
ignored
20 packages
- nym
- crunch
- git-brunch
- y-cruncher
- speedcrunch
- ocaml-crunch
- untrunc-anthwlock
- ocamlPackages.crunch
- gnomeExtensions.runcat
- haskellPackages.git-brunch
- ocamlPackages_latest.crunch
- perlPackages.StringTruncate
- python312Packages.truncnorm
- python313Packages.truncnorm
- python314Packages.truncnorm
- perl5Packages.StringTruncate
- haskellPackages.html-truncate
- perl538Packages.StringTruncate
- perl540Packages.StringTruncate
- vscode-extensions.42crunch.vscode-openapi
3 weeks, 5 days ago
-
@LeSuisse
accepted
3 weeks, 5 days ago
-
@LeSuisse
published on GitHub
3 weeks, 5 days ago
runc: Malicious image with /dev symlink can trigger limited host filesystem integrity violations
runc
-
==>= 1.4.0-rc.1, < 1.4.3
-
==< 1.3.6
-
==>= 1.5.0-rc.1, < 1.5.0-rc.3
HTML::Gumbo versions before 0.19 for Perl disclose heap memory via type confusion
Permalink
CVE-2025-15646
9.8 CRITICAL
-
CVSS version (CVSS): 3.1
-
Attack Vector (AV): Network (N)
-
Attack Complexity (AC): Low (L)
-
Privileges Required (PR): None (N)
-
User Interaction (UI): None (N)
-
Scope (S): Unchanged (U)
-
Confidentiality (C): High (H)
-
Integrity (I): High (H)
-
Availability (A): High (H)
-
Modified Attack Vector (MAV): Network (N)
-
Modified Attack Complexity (MAC): Low (L)
-
Modified Privileges Required (MPR): None (N)
-
Modified User Interaction (MUI): None (N)
-
Modified Confidentiality (MC): High (H)
-
Modified Scope (MS): Unchanged (U)
-
Modified Integrity (MI): High (H)
-
Modified Availability (MA): High (H)
updated
3 weeks, 5 days ago
by @LeSuisse
Activity log
-
Created suggestion
3 weeks, 6 days ago
-
@LeSuisse
accepted
3 weeks, 5 days ago
-
@LeSuisse
published on GitHub
3 weeks, 5 days ago
HTML::Gumbo versions before 0.19 for Perl disclose heap memory via type confusion
wagtail: security issues < 7.4.2
Permalink
CVE-2026-54263
7.3 HIGH
-
CVSS version (CVSS): 3.1
-
Attack Vector (AV): Network (N)
-
Attack Complexity (AC): Low (L)
-
Privileges Required (PR): Low (L)
-
User Interaction (UI): Required (R)
-
Scope (S): Unchanged (U)
-
Confidentiality (C): High (H)
-
Integrity (I): High (H)
-
Availability (A): None (N)
-
Modified Attack Vector (MAV): Network (N)
-
Modified Attack Complexity (MAC): Low (L)
-
Modified Privileges Required (MPR): Low (L)
-
Modified User Interaction (MUI): Required (R)
-
Modified Confidentiality (MC): High (H)
-
Modified Scope (MS): Unchanged (U)
-
Modified Integrity (MI): High (H)
-
Modified Availability (MA): None (N)
updated
3 weeks, 5 days ago
by @LeSuisse
Activity log
-
Created suggestion
3 weeks, 6 days ago
-
@LeSuisse
ignored
9 packages
- python312Packages.wagtail-localize
- python313Packages.wagtail-localize
- python314Packages.wagtail-localize
- python312Packages.wagtail-factories
- python313Packages.wagtail-factories
- python314Packages.wagtail-factories
- python312Packages.wagtail-modeladmin
- python313Packages.wagtail-modeladmin
- python314Packages.wagtail-modeladmin
3 weeks, 5 days ago
-
@LeSuisse
accepted
3 weeks, 5 days ago
-
@LeSuisse
published on GitHub
3 weeks, 5 days ago
Wagtail: Reflected XSS in dynamic image URL generator view
wagtail
-
==>= 7.4.0, < 7.4.2
-
==< 7.0.8
-
==>= 7.1.0, < 7.3.3
Permalink
CVE-2026-54260
4.3 MEDIUM
-
CVSS version (CVSS): 3.1
-
Attack Vector (AV): Network (N)
-
Attack Complexity (AC): Low (L)
-
Privileges Required (PR): Low (L)
-
User Interaction (UI): None (N)
-
Scope (S): Unchanged (U)
-
Confidentiality (C): None (N)
-
Integrity (I): None (N)
-
Availability (A): Low (L)
-
Modified Attack Vector (MAV): Network (N)
-
Modified Attack Complexity (MAC): Low (L)
-
Modified Privileges Required (MPR): Low (L)
-
Modified User Interaction (MUI): None (N)
-
Modified Confidentiality (MC): None (N)
-
Modified Scope (MS): Unchanged (U)
-
Modified Integrity (MI): None (N)
-
Modified Availability (MA): Low (L)
updated
3 weeks, 5 days ago
by @LeSuisse
Activity log
-
Created suggestion
3 weeks, 6 days ago
-
@LeSuisse
ignored
9 packages
- python312Packages.wagtail-localize
- python313Packages.wagtail-localize
- python314Packages.wagtail-localize
- python312Packages.wagtail-factories
- python313Packages.wagtail-factories
- python314Packages.wagtail-factories
- python312Packages.wagtail-modeladmin
- python313Packages.wagtail-modeladmin
- python314Packages.wagtail-modeladmin
3 weeks, 5 days ago
-
@LeSuisse
accepted
3 weeks, 5 days ago
-
@LeSuisse
published on GitHub
3 weeks, 5 days ago
Wagtail: Denial of service via unbounded filter specs in the image preview
wagtail
-
==>= 7.4.0, < 7.4.2
-
==< 7.0.8
-
==>= 7.1.0, < 7.3.3
Permalink
CVE-2026-54259
4.3 MEDIUM
-
CVSS version (CVSS): 3.1
-
Attack Vector (AV): Network (N)
-
Attack Complexity (AC): Low (L)
-
Privileges Required (PR): Low (L)
-
User Interaction (UI): None (N)
-
Scope (S): Unchanged (U)
-
Confidentiality (C): Low (L)
-
Integrity (I): None (N)
-
Availability (A): None (N)
-
Modified Attack Vector (MAV): Network (N)
-
Modified Attack Complexity (MAC): Low (L)
-
Modified Privileges Required (MPR): Low (L)
-
Modified User Interaction (MUI): None (N)
-
Modified Confidentiality (MC): Low (L)
-
Modified Scope (MS): Unchanged (U)
-
Modified Integrity (MI): None (N)
-
Modified Availability (MA): None (N)
updated
3 weeks, 5 days ago
by @LeSuisse
Activity log
-
Created suggestion
3 weeks, 6 days ago
-
@LeSuisse
ignored
9 packages
- python312Packages.wagtail-localize
- python313Packages.wagtail-localize
- python314Packages.wagtail-localize
- python312Packages.wagtail-factories
- python313Packages.wagtail-factories
- python314Packages.wagtail-factories
- python312Packages.wagtail-modeladmin
- python313Packages.wagtail-modeladmin
- python314Packages.wagtail-modeladmin
3 weeks, 5 days ago
-
@LeSuisse
accepted
3 weeks, 5 days ago
-
@LeSuisse
published on GitHub
3 weeks, 5 days ago
Wagtail: Improper restriction handling on Documents and Images chosen endpoints
wagtail
-
==>= 7.4.0, < 7.4.2
-
==< 7.0.8
-
==>= 7.1.0, < 7.3.3
Permalink
CVE-2026-54262
4.3 MEDIUM
-
CVSS version (CVSS): 3.1
-
Attack Vector (AV): Network (N)
-
Attack Complexity (AC): Low (L)
-
Privileges Required (PR): Low (L)
-
User Interaction (UI): None (N)
-
Scope (S): Unchanged (U)
-
Confidentiality (C): Low (L)
-
Integrity (I): None (N)
-
Availability (A): None (N)
-
Modified Attack Vector (MAV): Network (N)
-
Modified Attack Complexity (MAC): Low (L)
-
Modified Privileges Required (MPR): Low (L)
-
Modified User Interaction (MUI): None (N)
-
Modified Confidentiality (MC): Low (L)
-
Modified Scope (MS): Unchanged (U)
-
Modified Integrity (MI): None (N)
-
Modified Availability (MA): None (N)
updated
3 weeks, 5 days ago
by @LeSuisse
Activity log
-
Created suggestion
3 weeks, 6 days ago
-
@LeSuisse
ignored
9 packages
- python312Packages.wagtail-localize
- python313Packages.wagtail-localize
- python314Packages.wagtail-localize
- python312Packages.wagtail-factories
- python313Packages.wagtail-factories
- python314Packages.wagtail-factories
- python312Packages.wagtail-modeladmin
- python313Packages.wagtail-modeladmin
- python314Packages.wagtail-modeladmin
3 weeks, 5 days ago
-
@LeSuisse
accepted
3 weeks, 5 days ago
-
@LeSuisse
published on GitHub
3 weeks, 5 days ago
Wagtail: Pages translations can be created without page permissions when using simple_translation
wagtail
-
==>= 7.4.0, < 7.4.2
-
==< 7.0.8
-
==>= 7.1.0, < 7.3.3
Permalink
CVE-2026-54261
6.5 MEDIUM
-
CVSS version (CVSS): 3.1
-
Attack Vector (AV): Network (N)
-
Attack Complexity (AC): Low (L)
-
Privileges Required (PR): Low (L)
-
User Interaction (UI): None (N)
-
Scope (S): Unchanged (U)
-
Confidentiality (C): High (H)
-
Integrity (I): None (N)
-
Availability (A): None (N)
-
Modified Attack Vector (MAV): Network (N)
-
Modified Attack Complexity (MAC): Low (L)
-
Modified Privileges Required (MPR): Low (L)
-
Modified User Interaction (MUI): None (N)
-
Modified Confidentiality (MC): High (H)
-
Modified Scope (MS): Unchanged (U)
-
Modified Integrity (MI): None (N)
-
Modified Availability (MA): None (N)
updated
3 weeks, 5 days ago
by @LeSuisse
Activity log
-
Created suggestion
3 weeks, 6 days ago
-
@LeSuisse
ignored
9 packages
- python312Packages.wagtail-localize
- python313Packages.wagtail-localize
- python314Packages.wagtail-localize
- python312Packages.wagtail-factories
- python313Packages.wagtail-factories
- python314Packages.wagtail-factories
- python312Packages.wagtail-modeladmin
- python313Packages.wagtail-modeladmin
- python314Packages.wagtail-modeladmin
3 weeks, 5 days ago
-
@LeSuisse
accepted
3 weeks, 5 days ago
-
@LeSuisse
published on GitHub
3 weeks, 5 days ago
Wagtail: Improper permission handling in image preview
wagtail
-
==>= 7.4.0, < 7.4.2
-
==< 7.0.8
-
==>= 7.1.0, < 7.3.3
containerd: security issues < 2.3.2
Permalink
CVE-2026-50195
5.6 MEDIUM
-
CVSS version (CVSS): 4.0
-
Attack Vector (AV): Network (N)
-
Attack Complexity (AC): Low (L)
-
Attack Requirement (AT): Present (P)
-
Privileges Required (PR): Low (L)
-
User Interaction (UI): None (N)
-
Vulnerable System Impact Confidentiality (VC): None (N)
-
Vulnerable System Impact Integrity (VI): Low (L)
-
Vulnerable System Impact Availability (VA): None (N)
-
Subsequent System Impact Confidentiality (SC): High (H)
-
Subsequent System Impact Integrity (SI): High (H)
-
Subsequent System Impact Availability (SA): Low (L)
-
Modified Attack Vector (MAV): Network (N)
-
Modified Attack Complexity (MAC): Low (L)
-
Modified Attack Requirement (MAT): Present (P)
-
Modified Privileges Required (MPR): Low (L)
-
Modified User Interaction (MUI): None (N)
-
Modified Vulnerable System Impact Confidentiality (MVC): None (N)
-
Modified Vulnerable System Impact Integrity (MVI): Low (L)
-
Modified Vulnerable System Impact Availability (MVA): None (N)
-
Modified Subsequent System Impact Confidentiality (MSC): High (H)
-
Modified Subsequent System Impact Integrity (MSI): High (H)
-
Modified Subsequent System Impact Availability (MSA): Low (L)
-
Safety (S): Not Defined (X)
-
Automatable (AU): Not Defined (X)
-
Recovery (R): Not Defined (X)
-
Value Density (V): Not Defined (X)
-
Vulnerability Response Effort (RE): Not Defined (X)
-
Provider Urgency (U): Not Defined (X)
-
Confidentiality Req. (CR): Not Defined (X)
-
Integrity Req. (IR): Not Defined (X)
-
Availability Req. (AR): Not Defined (X)
-
Exploit Maturity (E): Not Defined (X)
updated
3 weeks, 5 days ago
by @LeSuisse
Activity log
-
Created suggestion
3 weeks, 6 days ago
-
@LeSuisse
ignored
package nomad-driver-containerd
3 weeks, 5 days ago
-
@LeSuisse
accepted
3 weeks, 5 days ago
-
@LeSuisse
published on GitHub
3 weeks, 5 days ago
containerd: CRI checkpoint import allows local image tag poisoning
containerd
-
==>= 2.1.0, < 2.1.9
-
==>= 2.2.0, < 2.2.5
-
==>= 2.3.0, < 2.3.2
Permalink
CVE-2026-47262
5.3 MEDIUM
-
CVSS version (CVSS): 4.0
-
Attack Vector (AV): Network (N)
-
Attack Complexity (AC): Low (L)
-
Attack Requirement (AT): None (N)
-
Privileges Required (PR): Low (L)
-
User Interaction (UI): None (N)
-
Vulnerable System Impact Confidentiality (VC): None (N)
-
Vulnerable System Impact Integrity (VI): None (N)
-
Vulnerable System Impact Availability (VA): Low (L)
-
Subsequent System Impact Confidentiality (SC): None (N)
-
Subsequent System Impact Integrity (SI): None (N)
-
Subsequent System Impact Availability (SA): None (N)
-
Modified Attack Vector (MAV): Network (N)
-
Modified Attack Complexity (MAC): Low (L)
-
Modified Attack Requirement (MAT): None (N)
-
Modified Privileges Required (MPR): Low (L)
-
Modified User Interaction (MUI): None (N)
-
Modified Vulnerable System Impact Confidentiality (MVC): None (N)
-
Modified Vulnerable System Impact Integrity (MVI): None (N)
-
Modified Vulnerable System Impact Availability (MVA): Low (L)
-
Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
-
Modified Subsequent System Impact Integrity (MSI): Negligible (N)
-
Modified Subsequent System Impact Availability (MSA): Negligible (N)
-
Safety (S): Not Defined (X)
-
Automatable (AU): Not Defined (X)
-
Recovery (R): Not Defined (X)
-
Value Density (V): Not Defined (X)
-
Vulnerability Response Effort (RE): Not Defined (X)
-
Provider Urgency (U): Not Defined (X)
-
Confidentiality Req. (CR): Not Defined (X)
-
Integrity Req. (IR): Not Defined (X)
-
Availability Req. (AR): Not Defined (X)
-
Exploit Maturity (E): Not Defined (X)
updated
3 weeks, 5 days ago
by @LeSuisse
Activity log
-
Created suggestion
3 weeks, 6 days ago
-
@LeSuisse
ignored
package nomad-driver-containerd
3 weeks, 5 days ago
-
@LeSuisse
accepted
3 weeks, 5 days ago
-
@LeSuisse
published on GitHub
3 weeks, 5 days ago
containerd image-triggered runtime DoS via unbounded group parsing
containerd
-
==>= 1.7.0, < 1.7.33
-
==>= 2.2.0, < 2.2.5
-
==>= 2.0.0, < 2.0.10
-
==>= 2.1.0, < 2.1.9
-
==>= 2.3.0, < 2.3.2
Permalink
CVE-2026-53489
8.2 HIGH
-
CVSS version (CVSS): 4.0
-
Attack Vector (AV): Local (L)
-
Attack Complexity (AC): Low (L)
-
Attack Requirement (AT): None (N)
-
Privileges Required (PR): None (N)
-
User Interaction (UI): None (N)
-
Vulnerable System Impact Confidentiality (VC): High (H)
-
Vulnerable System Impact Integrity (VI): None (N)
-
Vulnerable System Impact Availability (VA): None (N)
-
Subsequent System Impact Confidentiality (SC): High (H)
-
Subsequent System Impact Integrity (SI): None (N)
-
Subsequent System Impact Availability (SA): None (N)
-
Modified Attack Vector (MAV): Local (L)
-
Modified Attack Complexity (MAC): Low (L)
-
Modified Attack Requirement (MAT): None (N)
-
Modified Privileges Required (MPR): None (N)
-
Modified User Interaction (MUI): None (N)
-
Modified Vulnerable System Impact Confidentiality (MVC): High (H)
-
Modified Vulnerable System Impact Integrity (MVI): None (N)
-
Modified Vulnerable System Impact Availability (MVA): None (N)
-
Modified Subsequent System Impact Confidentiality (MSC): High (H)
-
Modified Subsequent System Impact Integrity (MSI): Negligible (N)
-
Modified Subsequent System Impact Availability (MSA): Negligible (N)
-
Safety (S): Not Defined (X)
-
Automatable (AU): Not Defined (X)
-
Recovery (R): Not Defined (X)
-
Value Density (V): Not Defined (X)
-
Vulnerability Response Effort (RE): Not Defined (X)
-
Provider Urgency (U): Not Defined (X)
-
Confidentiality Req. (CR): Not Defined (X)
-
Integrity Req. (IR): Not Defined (X)
-
Availability Req. (AR): Not Defined (X)
-
Exploit Maturity (E): Not Defined (X)
updated
3 weeks, 5 days ago
by @LeSuisse
Activity log
-
Created suggestion
3 weeks, 6 days ago
-
@LeSuisse
ignored
package nomad-driver-containerd
3 weeks, 5 days ago
-
@LeSuisse
accepted
3 weeks, 5 days ago
-
@LeSuisse
published on GitHub
3 weeks, 5 days ago
containerd: Arbitrary host CRI log file read via symlink following in CRI checkpoint restore
containerd
-
==>= 2.1.0, < 2.1.9
-
==>= 2.2.0, < 2.2.5
-
==>= 2.3.0, < 2.3.2
Permalink
CVE-2026-53488
9.4 CRITICAL
-
CVSS version (CVSS): 4.0
-
Attack Vector (AV): Local (L)
-
Attack Complexity (AC): Low (L)
-
Attack Requirement (AT): None (N)
-
Privileges Required (PR): None (N)
-
User Interaction (UI): None (N)
-
Vulnerable System Impact Confidentiality (VC): High (H)
-
Vulnerable System Impact Integrity (VI): High (H)
-
Vulnerable System Impact Availability (VA): High (H)
-
Subsequent System Impact Confidentiality (SC): High (H)
-
Subsequent System Impact Integrity (SI): High (H)
-
Subsequent System Impact Availability (SA): High (H)
-
Modified Attack Vector (MAV): Local (L)
-
Modified Attack Complexity (MAC): Low (L)
-
Modified Attack Requirement (MAT): None (N)
-
Modified Privileges Required (MPR): None (N)
-
Modified User Interaction (MUI): None (N)
-
Modified Vulnerable System Impact Confidentiality (MVC): High (H)
-
Modified Vulnerable System Impact Integrity (MVI): High (H)
-
Modified Vulnerable System Impact Availability (MVA): High (H)
-
Modified Subsequent System Impact Confidentiality (MSC): High (H)
-
Modified Subsequent System Impact Integrity (MSI): High (H)
-
Modified Subsequent System Impact Availability (MSA): High (H)
-
Safety (S): Not Defined (X)
-
Automatable (AU): Not Defined (X)
-
Recovery (R): Not Defined (X)
-
Value Density (V): Not Defined (X)
-
Vulnerability Response Effort (RE): Not Defined (X)
-
Provider Urgency (U): Not Defined (X)
-
Confidentiality Req. (CR): Not Defined (X)
-
Integrity Req. (IR): Not Defined (X)
-
Availability Req. (AR): Not Defined (X)
-
Exploit Maturity (E): Not Defined (X)
updated
3 weeks, 5 days ago
by @LeSuisse
Activity log
-
Created suggestion
3 weeks, 6 days ago
-
@LeSuisse
ignored
package nomad-driver-containerd
3 weeks, 5 days ago
-
@LeSuisse
accepted
3 weeks, 5 days ago
-
@LeSuisse
published on GitHub
3 weeks, 5 days ago
containerd CRI plugin: — image-config `LABEL` flows to restart-monitor `binary://` logger: host-root command execution from an image pull
containerd
-
==>= 2.2.0, < 2.2.5
-
==>= 2.0.0, < 2.0.10
-
==>= 2.1.0, < 2.1.9
-
==>= 2.3.0, < 2.3.2
-
==< 1.7.33
Permalink
CVE-2026-53492
8.4 HIGH
-
CVSS version (CVSS): 4.0
-
Attack Vector (AV): Network (N)
-
Attack Complexity (AC): Low (L)
-
Attack Requirement (AT): None (N)
-
Privileges Required (PR): Low (L)
-
User Interaction (UI): None (N)
-
Vulnerable System Impact Confidentiality (VC): None (N)
-
Vulnerable System Impact Integrity (VI): High (H)
-
Vulnerable System Impact Availability (VA): None (N)
-
Subsequent System Impact Confidentiality (SC): High (H)
-
Subsequent System Impact Integrity (SI): High (H)
-
Subsequent System Impact Availability (SA): None (N)
-
Modified Attack Vector (MAV): Network (N)
-
Modified Attack Complexity (MAC): Low (L)
-
Modified Attack Requirement (MAT): None (N)
-
Modified Privileges Required (MPR): Low (L)
-
Modified User Interaction (MUI): None (N)
-
Modified Vulnerable System Impact Confidentiality (MVC): None (N)
-
Modified Vulnerable System Impact Integrity (MVI): High (H)
-
Modified Vulnerable System Impact Availability (MVA): None (N)
-
Modified Subsequent System Impact Confidentiality (MSC): High (H)
-
Modified Subsequent System Impact Integrity (MSI): High (H)
-
Modified Subsequent System Impact Availability (MSA): Negligible (N)
-
Safety (S): Not Defined (X)
-
Automatable (AU): Not Defined (X)
-
Recovery (R): Not Defined (X)
-
Value Density (V): Not Defined (X)
-
Vulnerability Response Effort (RE): Not Defined (X)
-
Provider Urgency (U): Not Defined (X)
-
Confidentiality Req. (CR): Not Defined (X)
-
Integrity Req. (IR): Not Defined (X)
-
Availability Req. (AR): Not Defined (X)
-
Exploit Maturity (E): Not Defined (X)
updated
3 weeks, 5 days ago
by @LeSuisse
Activity log
-
Created suggestion
3 weeks, 6 days ago
-
@LeSuisse
ignored
package nomad-driver-containerd
3 weeks, 5 days ago
-
@LeSuisse
accepted
3 weeks, 5 days ago
-
@LeSuisse
published on GitHub
3 weeks, 5 days ago
containerd CRI checkpoint restore CDI annotation smuggling
containerd
-
==>= 2.1.0, < 2.1.9
-
==>= 2.2.0, < 2.2.5
-
==>= 2.3.0, < 2.3.2
containerd user ID handling bypass allows runAsNonRoot evasion
Permalink
CVE-2026-46680
7.3 HIGH
-
CVSS version (CVSS): 4.0
-
Attack Vector (AV): Local (L)
-
Attack Complexity (AC): Low (L)
-
Attack Requirement (AT): Present (P)
-
Privileges Required (PR): None (N)
-
User Interaction (UI): Passive (P)
-
Vulnerable System Impact Confidentiality (VC): High (H)
-
Vulnerable System Impact Integrity (VI): High (H)
-
Vulnerable System Impact Availability (VA): High (H)
-
Subsequent System Impact Confidentiality (SC): None (N)
-
Subsequent System Impact Integrity (SI): None (N)
-
Subsequent System Impact Availability (SA): None (N)
-
Modified Attack Vector (MAV): Local (L)
-
Modified Attack Complexity (MAC): Low (L)
-
Modified Attack Requirement (MAT): Present (P)
-
Modified Privileges Required (MPR): None (N)
-
Modified User Interaction (MUI): Passive (P)
-
Modified Vulnerable System Impact Confidentiality (MVC): High (H)
-
Modified Vulnerable System Impact Integrity (MVI): High (H)
-
Modified Vulnerable System Impact Availability (MVA): High (H)
-
Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
-
Modified Subsequent System Impact Integrity (MSI): Negligible (N)
-
Modified Subsequent System Impact Availability (MSA): Negligible (N)
-
Safety (S): Not Defined (X)
-
Automatable (AU): Not Defined (X)
-
Recovery (R): Not Defined (X)
-
Value Density (V): Not Defined (X)
-
Vulnerability Response Effort (RE): Not Defined (X)
-
Provider Urgency (U): Not Defined (X)
-
Confidentiality Req. (CR): Not Defined (X)
-
Integrity Req. (IR): Not Defined (X)
-
Availability Req. (AR): Not Defined (X)
-
Exploit Maturity (E): Not Defined (X)
updated
3 weeks, 5 days ago
by @LeSuisse
Activity log
-
Created suggestion
3 weeks, 6 days ago
-
@LeSuisse
ignored
package nomad-driver-containerd
3 weeks, 5 days ago
-
@LeSuisse
accepted
3 weeks, 5 days ago
-
@LeSuisse
published on GitHub
3 weeks, 5 days ago
containerd user ID handling bypass allows runAsNonRoot evasion
containerd
-
==>= 2.0.10, < 2.2.4
-
==< 1.7.32
-
==>= 2.0.4, < 2.0.9
-
==>= 2.2.5, < 2.3.1
MediaWiki: seucrity issues < 1.45.4
Permalink
CVE-2026-58037
0.0 NONE
-
CVSS version (CVSS): 4.0
-
Attack Vector (AV): Network (N)
-
Attack Complexity (AC): Low (L)
-
Attack Requirement (AT): None (N)
-
Privileges Required (PR): Low (L)
-
User Interaction (UI): Active (A)
-
Vulnerable System Impact Confidentiality (VC): None (N)
-
Vulnerable System Impact Integrity (VI): None (N)
-
Vulnerable System Impact Availability (VA): None (N)
-
Subsequent System Impact Confidentiality (SC): None (N)
-
Subsequent System Impact Integrity (SI): None (N)
-
Subsequent System Impact Availability (SA): None (N)
-
Modified Attack Vector (MAV): Network (N)
-
Modified Attack Complexity (MAC): Low (L)
-
Modified Attack Requirement (MAT): None (N)
-
Modified Privileges Required (MPR): Low (L)
-
Modified User Interaction (MUI): Active (A)
-
Modified Vulnerable System Impact Confidentiality (MVC): None (N)
-
Modified Vulnerable System Impact Integrity (MVI): None (N)
-
Modified Vulnerable System Impact Availability (MVA): None (N)
-
Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
-
Modified Subsequent System Impact Integrity (MSI): Negligible (N)
-
Modified Subsequent System Impact Availability (MSA): Negligible (N)
-
Safety (S): Not Defined (X)
-
Automatable (AU): Not Defined (X)
-
Recovery (R): Not Defined (X)
-
Value Density (V): Not Defined (X)
-
Vulnerability Response Effort (RE): Not Defined (X)
-
Provider Urgency (U): Not Defined (X)
-
Confidentiality Req. (CR): Not Defined (X)
-
Integrity Req. (IR): Not Defined (X)
-
Availability Req. (AR): Not Defined (X)
-
Exploit Maturity (E): Not Defined (X)
updated
3 weeks, 5 days ago
by @LeSuisse
Activity log
-
Created suggestion
3 weeks, 6 days ago
-
@LeSuisse
ignored
2 packages
- python313Packages.mediawiki-langcodes
- python314Packages.mediawiki-langcodes
3 weeks, 5 days ago
-
@LeSuisse
accepted
3 weeks, 5 days ago
-
@LeSuisse
published on GitHub
3 weeks, 5 days ago
Core log entries for exceptions and XSS issues in log entry formatting code that may be caused by user-controlled input
MediaWiki
-
<1.46.0, 1.45.4, 1.44.6, 1.43.9
Permalink
CVE-2026-58028
0.0 NONE
-
CVSS version (CVSS): 4.0
-
Attack Vector (AV): Network (N)
-
Attack Complexity (AC): Low (L)
-
Attack Requirement (AT): None (N)
-
Privileges Required (PR): Low (L)
-
User Interaction (UI): None (N)
-
Vulnerable System Impact Confidentiality (VC): None (N)
-
Vulnerable System Impact Integrity (VI): None (N)
-
Vulnerable System Impact Availability (VA): None (N)
-
Subsequent System Impact Confidentiality (SC): None (N)
-
Subsequent System Impact Integrity (SI): None (N)
-
Subsequent System Impact Availability (SA): None (N)
-
Modified Attack Vector (MAV): Network (N)
-
Modified Attack Complexity (MAC): Low (L)
-
Modified Attack Requirement (MAT): None (N)
-
Modified Privileges Required (MPR): Low (L)
-
Modified User Interaction (MUI): None (N)
-
Modified Vulnerable System Impact Confidentiality (MVC): None (N)
-
Modified Vulnerable System Impact Integrity (MVI): None (N)
-
Modified Vulnerable System Impact Availability (MVA): None (N)
-
Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
-
Modified Subsequent System Impact Integrity (MSI): Negligible (N)
-
Modified Subsequent System Impact Availability (MSA): Negligible (N)
-
Safety (S): Not Defined (X)
-
Automatable (AU): Not Defined (X)
-
Recovery (R): Not Defined (X)
-
Value Density (V): Not Defined (X)
-
Vulnerability Response Effort (RE): Not Defined (X)
-
Provider Urgency (U): Not Defined (X)
-
Confidentiality Req. (CR): Not Defined (X)
-
Integrity Req. (IR): Not Defined (X)
-
Availability Req. (AR): Not Defined (X)
-
Exploit Maturity (E): Not Defined (X)
updated
3 weeks, 5 days ago
by @LeSuisse
Activity log
-
Created suggestion
3 weeks, 6 days ago
-
@LeSuisse
ignored
2 packages
- python313Packages.mediawiki-langcodes
- python314Packages.mediawiki-langcodes
3 weeks, 5 days ago
-
@LeSuisse
accepted
3 weeks, 5 days ago
-
@LeSuisse
published on GitHub
3 weeks, 5 days ago
Pretty-printed API output combined with centralauthtoken allows XSS with certain gadgets
MediaWiki
-
<1.46.0, 1.45.4, 1.44.6, 1.43.9
CentralAuth
-
<1.46.0, 1.45.4, 1.44.6, 1.43.9
Permalink
CVE-2026-58024
5.1 MEDIUM
-
CVSS version (CVSS): 4.0
-
Attack Vector (AV): Network (N)
-
Attack Complexity (AC): Low (L)
-
Attack Requirement (AT): None (N)
-
Privileges Required (PR): Low (L)
-
User Interaction (UI): Passive (P)
-
Vulnerable System Impact Confidentiality (VC): Low (L)
-
Vulnerable System Impact Integrity (VI): None (N)
-
Vulnerable System Impact Availability (VA): None (N)
-
Subsequent System Impact Confidentiality (SC): None (N)
-
Subsequent System Impact Integrity (SI): None (N)
-
Subsequent System Impact Availability (SA): None (N)
-
Modified Attack Vector (MAV): Network (N)
-
Modified Attack Complexity (MAC): Low (L)
-
Modified Attack Requirement (MAT): None (N)
-
Modified Privileges Required (MPR): Low (L)
-
Modified User Interaction (MUI): Passive (P)
-
Modified Vulnerable System Impact Confidentiality (MVC): Low (L)
-
Modified Vulnerable System Impact Integrity (MVI): None (N)
-
Modified Vulnerable System Impact Availability (MVA): None (N)
-
Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
-
Modified Subsequent System Impact Integrity (MSI): Negligible (N)
-
Modified Subsequent System Impact Availability (MSA): Negligible (N)
-
Safety (S): Not Defined (X)
-
Automatable (AU): Not Defined (X)
-
Recovery (R): Not Defined (X)
-
Value Density (V): Not Defined (X)
-
Vulnerability Response Effort (RE): Not Defined (X)
-
Provider Urgency (U): Not Defined (X)
-
Confidentiality Req. (CR): Not Defined (X)
-
Integrity Req. (IR): Not Defined (X)
-
Availability Req. (AR): Not Defined (X)
-
Exploit Maturity (E): Not Defined (X)
updated
3 weeks, 5 days ago
by @LeSuisse
Activity log
-
Created suggestion
3 weeks, 6 days ago
-
@LeSuisse
ignored
2 packages
- python313Packages.mediawiki-langcodes
- python314Packages.mediawiki-langcodes
3 weeks, 5 days ago
-
@LeSuisse
accepted
3 weeks, 5 days ago
-
@LeSuisse
published on GitHub
3 weeks, 5 days ago
API identification of users on private wikis
MediaWiki
-
<1.46.0, 1.45.4, 1.44.6, 1.43.9
Permalink
CVE-2026-58029
5.3 MEDIUM
-
CVSS version (CVSS): 4.0
-
Attack Vector (AV): Network (N)
-
Attack Complexity (AC): Low (L)
-
Attack Requirement (AT): None (N)
-
Privileges Required (PR): None (N)
-
User Interaction (UI): Passive (P)
-
Vulnerable System Impact Confidentiality (VC): Low (L)
-
Vulnerable System Impact Integrity (VI): Low (L)
-
Vulnerable System Impact Availability (VA): None (N)
-
Subsequent System Impact Confidentiality (SC): Low (L)
-
Subsequent System Impact Integrity (SI): Low (L)
-
Subsequent System Impact Availability (SA): None (N)
-
Modified Attack Vector (MAV): Network (N)
-
Modified Attack Complexity (MAC): Low (L)
-
Modified Attack Requirement (MAT): None (N)
-
Modified Privileges Required (MPR): None (N)
-
Modified User Interaction (MUI): Passive (P)
-
Modified Vulnerable System Impact Confidentiality (MVC): Low (L)
-
Modified Vulnerable System Impact Integrity (MVI): Low (L)
-
Modified Vulnerable System Impact Availability (MVA): None (N)
-
Modified Subsequent System Impact Confidentiality (MSC): Low (L)
-
Modified Subsequent System Impact Integrity (MSI): Low (L)
-
Modified Subsequent System Impact Availability (MSA): Negligible (N)
-
Safety (S): Not Defined (X)
-
Automatable (AU): Not Defined (X)
-
Recovery (R): Not Defined (X)
-
Value Density (V): Not Defined (X)
-
Vulnerability Response Effort (RE): Not Defined (X)
-
Provider Urgency (U): Not Defined (X)
-
Confidentiality Req. (CR): Not Defined (X)
-
Integrity Req. (IR): Not Defined (X)
-
Availability Req. (AR): Not Defined (X)
-
Exploit Maturity (E): Not Defined (X)
updated
3 weeks, 5 days ago
by @LeSuisse
Activity log
-
Created suggestion
3 weeks, 6 days ago
-
@LeSuisse
ignored
2 packages
- python313Packages.mediawiki-langcodes
- python314Packages.mediawiki-langcodes
3 weeks, 5 days ago
-
@LeSuisse
accepted
3 weeks, 5 days ago
-
@LeSuisse
published on GitHub
3 weeks, 5 days ago
Full Account Takeover from BotPasswords and OAuth via action=changeauthenticationdata
MediaWiki
-
<1.46.0, 1.45.4, 1.44.6, 1.43.9
Permalink
CVE-2026-58033
5.3 MEDIUM
-
CVSS version (CVSS): 4.0
-
Attack Vector (AV): Network (N)
-
Attack Complexity (AC): Low (L)
-
Attack Requirement (AT): None (N)
-
Privileges Required (PR): None (N)
-
User Interaction (UI): Passive (P)
-
Vulnerable System Impact Confidentiality (VC): Low (L)
-
Vulnerable System Impact Integrity (VI): None (N)
-
Vulnerable System Impact Availability (VA): None (N)
-
Subsequent System Impact Confidentiality (SC): None (N)
-
Subsequent System Impact Integrity (SI): None (N)
-
Subsequent System Impact Availability (SA): None (N)
-
Modified Attack Vector (MAV): Network (N)
-
Modified Attack Complexity (MAC): Low (L)
-
Modified Attack Requirement (MAT): None (N)
-
Modified Privileges Required (MPR): None (N)
-
Modified User Interaction (MUI): Passive (P)
-
Modified Vulnerable System Impact Confidentiality (MVC): Low (L)
-
Modified Vulnerable System Impact Integrity (MVI): None (N)
-
Modified Vulnerable System Impact Availability (MVA): None (N)
-
Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
-
Modified Subsequent System Impact Integrity (MSI): Negligible (N)
-
Modified Subsequent System Impact Availability (MSA): Negligible (N)
-
Safety (S): Not Defined (X)
-
Automatable (AU): Not Defined (X)
-
Recovery (R): Not Defined (X)
-
Value Density (V): Not Defined (X)
-
Vulnerability Response Effort (RE): Not Defined (X)
-
Provider Urgency (U): Not Defined (X)
-
Confidentiality Req. (CR): Not Defined (X)
-
Integrity Req. (IR): Not Defined (X)
-
Availability Req. (AR): Not Defined (X)
-
Exploit Maturity (E): Not Defined (X)
updated
3 weeks, 5 days ago
by @LeSuisse
Activity log
-
Created suggestion
3 weeks, 6 days ago
-
@LeSuisse
ignored
2 packages
- python313Packages.mediawiki-langcodes
- python314Packages.mediawiki-langcodes
3 weeks, 5 days ago
-
@LeSuisse
accepted
3 weeks, 5 days ago
-
@LeSuisse
published on GitHub
3 weeks, 5 days ago
"Total number of distinct authors" statistic at action=info does not exclude revisions where the author name was deleted
MediaWiki
-
<1.46.0, 1.45.4, 1.44.6, 1.43.9
Permalink
CVE-2026-58035
0.0 NONE
-
CVSS version (CVSS): 4.0
-
Attack Vector (AV): Network (N)
-
Attack Complexity (AC): Low (L)
-
Attack Requirement (AT): None (N)
-
Privileges Required (PR): High (H)
-
User Interaction (UI): Passive (P)
-
Vulnerable System Impact Confidentiality (VC): None (N)
-
Vulnerable System Impact Integrity (VI): None (N)
-
Vulnerable System Impact Availability (VA): None (N)
-
Subsequent System Impact Confidentiality (SC): None (N)
-
Subsequent System Impact Integrity (SI): None (N)
-
Subsequent System Impact Availability (SA): None (N)
-
Modified Attack Vector (MAV): Network (N)
-
Modified Attack Complexity (MAC): Low (L)
-
Modified Attack Requirement (MAT): None (N)
-
Modified Privileges Required (MPR): High (H)
-
Modified User Interaction (MUI): Passive (P)
-
Modified Vulnerable System Impact Confidentiality (MVC): None (N)
-
Modified Vulnerable System Impact Integrity (MVI): None (N)
-
Modified Vulnerable System Impact Availability (MVA): None (N)
-
Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
-
Modified Subsequent System Impact Integrity (MSI): Negligible (N)
-
Modified Subsequent System Impact Availability (MSA): Negligible (N)
-
Safety (S): Not Defined (X)
-
Automatable (AU): Not Defined (X)
-
Recovery (R): Not Defined (X)
-
Value Density (V): Not Defined (X)
-
Vulnerability Response Effort (RE): Not Defined (X)
-
Provider Urgency (U): Not Defined (X)
-
Confidentiality Req. (CR): Not Defined (X)
-
Integrity Req. (IR): Not Defined (X)
-
Availability Req. (AR): Not Defined (X)
-
Exploit Maturity (E): Not Defined (X)
updated
3 weeks, 5 days ago
by @LeSuisse
Activity log
-
Created suggestion
3 weeks, 6 days ago
-
@LeSuisse
ignored
2 packages
- python313Packages.mediawiki-langcodes
- python314Packages.mediawiki-langcodes
3 weeks, 5 days ago
-
@LeSuisse
accepted
3 weeks, 5 days ago
-
@LeSuisse
published on GitHub
3 weeks, 5 days ago
Stored XSS through a system message in the codex version of Special:Block
Permalink
CVE-2026-58031
0.0 NONE
-
CVSS version (CVSS): 4.0
-
Attack Vector (AV): Network (N)
-
Attack Complexity (AC): Low (L)
-
Attack Requirement (AT): None (N)
-
Privileges Required (PR): Low (L)
-
User Interaction (UI): Passive (P)
-
Vulnerable System Impact Confidentiality (VC): None (N)
-
Vulnerable System Impact Integrity (VI): None (N)
-
Vulnerable System Impact Availability (VA): None (N)
-
Subsequent System Impact Confidentiality (SC): None (N)
-
Subsequent System Impact Integrity (SI): None (N)
-
Subsequent System Impact Availability (SA): None (N)
-
Modified Attack Vector (MAV): Network (N)
-
Modified Attack Complexity (MAC): Low (L)
-
Modified Attack Requirement (MAT): None (N)
-
Modified Privileges Required (MPR): Low (L)
-
Modified User Interaction (MUI): Passive (P)
-
Modified Vulnerable System Impact Confidentiality (MVC): None (N)
-
Modified Vulnerable System Impact Integrity (MVI): None (N)
-
Modified Vulnerable System Impact Availability (MVA): None (N)
-
Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
-
Modified Subsequent System Impact Integrity (MSI): Negligible (N)
-
Modified Subsequent System Impact Availability (MSA): Negligible (N)
-
Safety (S): Not Defined (X)
-
Automatable (AU): Not Defined (X)
-
Recovery (R): Not Defined (X)
-
Value Density (V): Not Defined (X)
-
Vulnerability Response Effort (RE): Not Defined (X)
-
Provider Urgency (U): Not Defined (X)
-
Confidentiality Req. (CR): Not Defined (X)
-
Integrity Req. (IR): Not Defined (X)
-
Availability Req. (AR): Not Defined (X)
-
Exploit Maturity (E): Not Defined (X)
updated
3 weeks, 5 days ago
by @LeSuisse
Activity log
-
Created suggestion
3 weeks, 6 days ago
-
@LeSuisse
ignored
2 packages
- python313Packages.mediawiki-langcodes
- python314Packages.mediawiki-langcodes
3 weeks, 5 days ago
-
@LeSuisse
accepted
3 weeks, 5 days ago
-
@LeSuisse
published on GitHub
3 weeks, 5 days ago
Stored i18n XSS in Special:ApiSandbox when a deprecated module is selected
Permalink
CVE-2026-58025
5.9 MEDIUM
-
CVSS version (CVSS): 4.0
-
Attack Vector (AV): Network (N)
-
Attack Complexity (AC): High (H)
-
Attack Requirement (AT): None (N)
-
Privileges Required (PR): High (H)
-
User Interaction (UI): None (N)
-
Vulnerable System Impact Confidentiality (VC): Low (L)
-
Vulnerable System Impact Integrity (VI): High (H)
-
Vulnerable System Impact Availability (VA): Low (L)
-
Subsequent System Impact Confidentiality (SC): Low (L)
-
Subsequent System Impact Integrity (SI): Low (L)
-
Subsequent System Impact Availability (SA): Low (L)
-
Modified Attack Vector (MAV): Network (N)
-
Modified Attack Complexity (MAC): High (H)
-
Modified Attack Requirement (MAT): None (N)
-
Modified Privileges Required (MPR): High (H)
-
Modified User Interaction (MUI): None (N)
-
Modified Vulnerable System Impact Confidentiality (MVC): Low (L)
-
Modified Vulnerable System Impact Integrity (MVI): High (H)
-
Modified Vulnerable System Impact Availability (MVA): Low (L)
-
Modified Subsequent System Impact Confidentiality (MSC): Low (L)
-
Modified Subsequent System Impact Integrity (MSI): Low (L)
-
Modified Subsequent System Impact Availability (MSA): Low (L)
-
Safety (S): Not Defined (X)
-
Automatable (AU): Not Defined (X)
-
Recovery (R): Not Defined (X)
-
Value Density (V): Not Defined (X)
-
Vulnerability Response Effort (RE): Not Defined (X)
-
Provider Urgency (U): Not Defined (X)
-
Confidentiality Req. (CR): Not Defined (X)
-
Integrity Req. (IR): Not Defined (X)
-
Availability Req. (AR): Not Defined (X)
-
Exploit Maturity (E): Not Defined (X)
updated
3 weeks, 5 days ago
by @LeSuisse
Activity log
-
Created suggestion
3 weeks, 6 days ago
-
@LeSuisse
ignored
2 packages
- python313Packages.mediawiki-langcodes
- python314Packages.mediawiki-langcodes
3 weeks, 5 days ago
-
@LeSuisse
accepted
3 weeks, 5 days ago
-
@LeSuisse
published on GitHub
3 weeks, 5 days ago
Remote Code Execution via Unsafe Deserialization in LogItem Import
MediaWiki
-
<1.46.0, 1.45.4, 1.44.6, 1.43.9
Permalink
CVE-2026-58026
0.0 NONE
-
CVSS version (CVSS): 4.0
-
Attack Vector (AV): Network (N)
-
Attack Complexity (AC): Low (L)
-
Attack Requirement (AT): None (N)
-
Privileges Required (PR): Low (L)
-
User Interaction (UI): Passive (P)
-
Vulnerable System Impact Confidentiality (VC): None (N)
-
Vulnerable System Impact Integrity (VI): None (N)
-
Vulnerable System Impact Availability (VA): None (N)
-
Subsequent System Impact Confidentiality (SC): None (N)
-
Subsequent System Impact Integrity (SI): None (N)
-
Subsequent System Impact Availability (SA): None (N)
-
Modified Attack Vector (MAV): Network (N)
-
Modified Attack Complexity (MAC): Low (L)
-
Modified Attack Requirement (MAT): None (N)
-
Modified Privileges Required (MPR): Low (L)
-
Modified User Interaction (MUI): Passive (P)
-
Modified Vulnerable System Impact Confidentiality (MVC): None (N)
-
Modified Vulnerable System Impact Integrity (MVI): None (N)
-
Modified Vulnerable System Impact Availability (MVA): None (N)
-
Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
-
Modified Subsequent System Impact Integrity (MSI): Negligible (N)
-
Modified Subsequent System Impact Availability (MSA): Negligible (N)
-
Safety (S): Not Defined (X)
-
Automatable (AU): Not Defined (X)
-
Recovery (R): Not Defined (X)
-
Value Density (V): Not Defined (X)
-
Vulnerability Response Effort (RE): Not Defined (X)
-
Provider Urgency (U): Not Defined (X)
-
Confidentiality Req. (CR): Not Defined (X)
-
Integrity Req. (IR): Not Defined (X)
-
Availability Req. (AR): Not Defined (X)
-
Exploit Maturity (E): Not Defined (X)
updated
3 weeks, 5 days ago
by @LeSuisse
Activity log
-
Created suggestion
3 weeks, 6 days ago
-
@LeSuisse
ignored
2 packages
- python313Packages.mediawiki-langcodes
- python314Packages.mediawiki-langcodes
3 weeks, 5 days ago
-
@LeSuisse
accepted
3 weeks, 5 days ago
-
@LeSuisse
published on GitHub
3 weeks, 5 days ago
$wgNonincludableNamespaces can be bypassed by embedding redirect in other namespaces
MediaWiki
-
<1.46.0, 1.45.4, 1.44.6, 1.43.9
Permalink
CVE-2026-58032
5.3 MEDIUM
-
CVSS version (CVSS): 4.0
-
Attack Vector (AV): Network (N)
-
Attack Complexity (AC): Low (L)
-
Attack Requirement (AT): None (N)
-
Privileges Required (PR): None (N)
-
User Interaction (UI): Passive (P)
-
Vulnerable System Impact Confidentiality (VC): Low (L)
-
Vulnerable System Impact Integrity (VI): None (N)
-
Vulnerable System Impact Availability (VA): None (N)
-
Subsequent System Impact Confidentiality (SC): None (N)
-
Subsequent System Impact Integrity (SI): None (N)
-
Subsequent System Impact Availability (SA): None (N)
-
Modified Attack Vector (MAV): Network (N)
-
Modified Attack Complexity (MAC): Low (L)
-
Modified Attack Requirement (MAT): None (N)
-
Modified Privileges Required (MPR): None (N)
-
Modified User Interaction (MUI): Passive (P)
-
Modified Vulnerable System Impact Confidentiality (MVC): Low (L)
-
Modified Vulnerable System Impact Integrity (MVI): None (N)
-
Modified Vulnerable System Impact Availability (MVA): None (N)
-
Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
-
Modified Subsequent System Impact Integrity (MSI): Negligible (N)
-
Modified Subsequent System Impact Availability (MSA): Negligible (N)
-
Safety (S): Not Defined (X)
-
Automatable (AU): Not Defined (X)
-
Recovery (R): Not Defined (X)
-
Value Density (V): Not Defined (X)
-
Vulnerability Response Effort (RE): Not Defined (X)
-
Provider Urgency (U): Not Defined (X)
-
Confidentiality Req. (CR): Not Defined (X)
-
Integrity Req. (IR): Not Defined (X)
-
Availability Req. (AR): Not Defined (X)
-
Exploit Maturity (E): Not Defined (X)
updated
3 weeks, 5 days ago
by @LeSuisse
Activity log
-
Created suggestion
3 weeks, 6 days ago
-
@LeSuisse
ignored
2 packages
- python313Packages.mediawiki-langcodes
- python314Packages.mediawiki-langcodes
3 weeks, 5 days ago
-
@LeSuisse
accepted
3 weeks, 5 days ago
-
@LeSuisse
published on GitHub
3 weeks, 5 days ago
mw.Api.getErrorMessage() may return injected HTML if used without errorformat=html
MediaWiki
-
<1.46.0, 1.45.4, 1.44.6, 1.43.9
open62541: security issues < 1.4.17
Permalink
CVE-2026-11946
7.5 HIGH
-
CVSS version (CVSS): 3.1
-
Attack Vector (AV): Network (N)
-
Attack Complexity (AC): Low (L)
-
Privileges Required (PR): None (N)
-
User Interaction (UI): None (N)
-
Scope (S): Unchanged (U)
-
Confidentiality (C): None (N)
-
Integrity (I): None (N)
-
Availability (A): High (H)
-
Modified Attack Vector (MAV): Network (N)
-
Modified Attack Complexity (MAC): Low (L)
-
Modified Privileges Required (MPR): None (N)
-
Modified User Interaction (MUI): None (N)
-
Modified Confidentiality (MC): None (N)
-
Modified Scope (MS): Unchanged (U)
-
Modified Integrity (MI): None (N)
-
Modified Availability (MA): High (H)
updated
3 weeks, 5 days ago
by @LeSuisse
Activity log
-
Created suggestion
3 weeks, 5 days ago
-
@LeSuisse
ignored
package open62541pp
3 weeks, 5 days ago
-
@LeSuisse
ignored
reference https://g…
3 weeks, 5 days ago
-
@LeSuisse
accepted
3 weeks, 5 days ago
-
@LeSuisse
published on GitHub
3 weeks, 5 days ago
GetEndpoints Memory Exhaustion in open62541
open62541
-
=<1.5.4
-
==master
-
=<1.4.16
Permalink
CVE-2026-33592
7.5 HIGH
-
CVSS version (CVSS): 3.1
-
Attack Vector (AV): Network (N)
-
Attack Complexity (AC): Low (L)
-
Privileges Required (PR): None (N)
-
User Interaction (UI): None (N)
-
Scope (S): Unchanged (U)
-
Confidentiality (C): None (N)
-
Integrity (I): None (N)
-
Availability (A): High (H)
-
Modified Attack Vector (MAV): Network (N)
-
Modified Attack Complexity (MAC): Low (L)
-
Modified Privileges Required (MPR): None (N)
-
Modified User Interaction (MUI): None (N)
-
Modified Confidentiality (MC): None (N)
-
Modified Scope (MS): Unchanged (U)
-
Modified Integrity (MI): None (N)
-
Modified Availability (MA): High (H)
updated
3 weeks, 5 days ago
by @LeSuisse
Activity log
-
Created suggestion
3 weeks, 5 days ago
-
@LeSuisse
ignored
package open62541pp
3 weeks, 5 days ago
-
@LeSuisse
ignored
reference https://g…
3 weeks, 5 days ago
-
@LeSuisse
accepted
3 weeks, 5 days ago
-
@LeSuisse
published on GitHub
3 weeks, 5 days ago
FindServers Memory Exhaustion in open62541
open62541
-
=<1.5.4
-
==master
-
=<1.4.16