Published issues
Permalink
CVE-2026-42294
8.2 HIGH
-
CVSS version (CVSS): 4.0
-
Attack Vector (AV): Network (N)
-
Attack Complexity (AC): Low (L)
-
Attack Requirement (AT): Present (P)
-
Privileges Required (PR): None (N)
-
User Interaction (UI): None (N)
-
Vulnerable System Impact Confidentiality (VC): None (N)
-
Vulnerable System Impact Integrity (VI): None (N)
-
Vulnerable System Impact Availability (VA): High (H)
-
Subsequent System Impact Confidentiality (SC): None (N)
-
Subsequent System Impact Integrity (SI): None (N)
-
Subsequent System Impact Availability (SA): None (N)
-
Modified Attack Vector (MAV): Network (N)
-
Modified Attack Complexity (MAC): Low (L)
-
Modified Attack Requirement (MAT): Present (P)
-
Modified Privileges Required (MPR): None (N)
-
Modified User Interaction (MUI): None (N)
-
Modified Vulnerable System Impact Confidentiality (MVC): None (N)
-
Modified Vulnerable System Impact Integrity (MVI): None (N)
-
Modified Vulnerable System Impact Availability (MVA): High (H)
-
Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
-
Modified Subsequent System Impact Integrity (MSI): Negligible (N)
-
Modified Subsequent System Impact Availability (MSA): Negligible (N)
-
Safety (S): Not Defined (X)
-
Automatable (AU): Not Defined (X)
-
Recovery (R): Not Defined (X)
-
Value Density (V): Not Defined (X)
-
Vulnerability Response Effort (RE): Not Defined (X)
-
Provider Urgency (U): Not Defined (X)
-
Confidentiality Req. (CR): Not Defined (X)
-
Integrity Req. (IR): Not Defined (X)
-
Availability Req. (AR): Not Defined (X)
-
Exploit Maturity (E): Not Defined (X)
updated
1 month, 2 weeks ago
by @LeSuisse
Activity log
-
Created suggestion
1 month, 2 weeks ago
-
@LeSuisse
ignored
reference https://g…
1 month, 2 weeks ago
-
@LeSuisse
accepted
1 month, 2 weeks ago
-
@LeSuisse
published on GitHub
1 month, 2 weeks ago
Argo Workflows: Unauthenticated Memory Exhaustion (DoS) in Webhook Interceptor
argo-workflows
-
==>= 4.0.0, < 4.0.5
-
==< 3.7.14
Permalink
CVE-2026-42258
5.8 MEDIUM
-
CVSS version (CVSS): 4.0
-
Attack Vector (AV): Local (L)
-
Attack Complexity (AC): High (H)
-
Attack Requirement (AT): Present (P)
-
Privileges Required (PR): None (N)
-
User Interaction (UI): Passive (P)
-
Vulnerable System Impact Confidentiality (VC): None (N)
-
Vulnerable System Impact Integrity (VI): High (H)
-
Vulnerable System Impact Availability (VA): Low (L)
-
Subsequent System Impact Confidentiality (SC): None (N)
-
Subsequent System Impact Integrity (SI): None (N)
-
Subsequent System Impact Availability (SA): None (N)
-
Modified Attack Vector (MAV): Local (L)
-
Modified Attack Complexity (MAC): High (H)
-
Modified Attack Requirement (MAT): Present (P)
-
Modified Privileges Required (MPR): None (N)
-
Modified User Interaction (MUI): Passive (P)
-
Modified Vulnerable System Impact Confidentiality (MVC): None (N)
-
Modified Vulnerable System Impact Integrity (MVI): High (H)
-
Modified Vulnerable System Impact Availability (MVA): Low (L)
-
Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
-
Modified Subsequent System Impact Integrity (MSI): Negligible (N)
-
Modified Subsequent System Impact Availability (MSA): Negligible (N)
-
Safety (S): Not Defined (X)
-
Automatable (AU): Not Defined (X)
-
Recovery (R): Not Defined (X)
-
Value Density (V): Not Defined (X)
-
Vulnerability Response Effort (RE): Not Defined (X)
-
Provider Urgency (U): Not Defined (X)
-
Confidentiality Req. (CR): Not Defined (X)
-
Integrity Req. (IR): Not Defined (X)
-
Availability Req. (AR): Not Defined (X)
-
Exploit Maturity (E): Not Defined (X)
updated
1 month, 2 weeks ago
by @LeSuisse
Activity log
-
Created suggestion
1 month, 2 weeks ago
-
@LeSuisse
ignored
2 references
1 month, 2 weeks ago
-
@LeSuisse
ignored
4 packages
- perl540Packages.NetIMAPClient
- perl538Packages.NetIMAPClient
- perl5Packages.NetIMAPClient
- perlPackages.NetIMAPClient
1 month, 2 weeks ago
-
@LeSuisse
accepted
1 month, 2 weeks ago
-
@LeSuisse
published on GitHub
1 month, 2 weeks ago
net-imap: Command Injection via unvalidated Symbol inputs
net-imap
-
==>= 0.6.0, < 0.6.4
-
==< 0.4.24
-
==>= 0.5.0, < 0.5.14
Permalink
CVE-2026-42574
7.5 HIGH
-
CVSS version (CVSS): 3.1
-
Attack Vector (AV): Network (N)
-
Attack Complexity (AC): Low (L)
-
Privileges Required (PR): None (N)
-
User Interaction (UI): None (N)
-
Scope (S): Unchanged (U)
-
Confidentiality (C): None (N)
-
Integrity (I): High (H)
-
Availability (A): None (N)
-
Modified Attack Vector (MAV): Network (N)
-
Modified Attack Complexity (MAC): Low (L)
-
Modified Privileges Required (MPR): None (N)
-
Modified User Interaction (MUI): None (N)
-
Modified Confidentiality (MC): None (N)
-
Modified Scope (MS): Unchanged (U)
-
Modified Integrity (MI): High (H)
-
Modified Availability (MA): None (N)
updated
1 month, 2 weeks ago
by @LeSuisse
Activity log
-
Created suggestion
1 month, 2 weeks ago
-
@LeSuisse
ignored
reference https://g…
1 month, 2 weeks ago
-
@LeSuisse
accepted
1 month, 2 weeks ago
-
@LeSuisse
published on GitHub
1 month, 2 weeks ago
apko dirFS has a symlink-following path traversal that allows multiple entry points to escape the build root
Permalink
CVE-2026-8120
2.1 LOW
-
CVSS version (CVSS): 4.0
-
Attack Vector (AV): Network (N)
-
Attack Complexity (AC): Low (L)
-
Attack Requirement (AT): None (N)
-
Privileges Required (PR): Low (L)
-
User Interaction (UI): None (N)
-
Vulnerable System Impact Confidentiality (VC): None (N)
-
Vulnerable System Impact Integrity (VI): None (N)
-
Vulnerable System Impact Availability (VA): Low (L)
-
Subsequent System Impact Confidentiality (SC): None (N)
-
Subsequent System Impact Integrity (SI): None (N)
-
Subsequent System Impact Availability (SA): None (N)
-
Exploit Maturity (E): POC (P)
-
Modified Attack Vector (MAV): Network (N)
-
Modified Attack Complexity (MAC): Low (L)
-
Modified Attack Requirement (MAT): None (N)
-
Modified Privileges Required (MPR): Low (L)
-
Modified User Interaction (MUI): None (N)
-
Modified Vulnerable System Impact Confidentiality (MVC): None (N)
-
Modified Vulnerable System Impact Integrity (MVI): None (N)
-
Modified Vulnerable System Impact Availability (MVA): Low (L)
-
Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
-
Modified Subsequent System Impact Integrity (MSI): Negligible (N)
-
Modified Subsequent System Impact Availability (MSA): Negligible (N)
-
Safety (S): Not Defined (X)
-
Automatable (AU): Not Defined (X)
-
Recovery (R): Not Defined (X)
-
Value Density (V): Not Defined (X)
-
Vulnerability Response Effort (RE): Not Defined (X)
-
Provider Urgency (U): Not Defined (X)
-
Confidentiality Req. (CR): Not Defined (X)
-
Integrity Req. (IR): Not Defined (X)
-
Availability Req. (AR): Not Defined (X)
updated
1 month, 2 weeks ago
by @LeSuisse
Activity log
-
Created suggestion
1 month, 2 weeks ago
-
@LeSuisse
ignored
package open5gs-webui
1 month, 2 weeks ago
-
@LeSuisse
ignored
3 references
1 month, 2 weeks ago
-
@LeSuisse
accepted
1 month, 2 weeks ago
-
@LeSuisse
published on GitHub
1 month, 2 weeks ago
Open5GS NSSF nnssf-handler.c denial of service
Open5GS
-
==2.7.1
-
==2.7.7
-
==2.7.4
-
==2.7.0
-
==2.7.3
-
==2.7.5
-
==2.7.6
-
==2.7.2
Permalink
CVE-2026-41163
8.7 HIGH
-
CVSS version (CVSS): 4.0
-
Attack Vector (AV): Network (N)
-
Attack Complexity (AC): Low (L)
-
Attack Requirement (AT): None (N)
-
Privileges Required (PR): None (N)
-
User Interaction (UI): None (N)
-
Vulnerable System Impact Confidentiality (VC): None (N)
-
Vulnerable System Impact Integrity (VI): High (H)
-
Vulnerable System Impact Availability (VA): None (N)
-
Subsequent System Impact Confidentiality (SC): None (N)
-
Subsequent System Impact Integrity (SI): None (N)
-
Subsequent System Impact Availability (SA): None (N)
-
Modified Attack Vector (MAV): Network (N)
-
Modified Attack Complexity (MAC): Low (L)
-
Modified Attack Requirement (MAT): None (N)
-
Modified Privileges Required (MPR): None (N)
-
Modified User Interaction (MUI): None (N)
-
Modified Vulnerable System Impact Confidentiality (MVC): None (N)
-
Modified Vulnerable System Impact Integrity (MVI): High (H)
-
Modified Vulnerable System Impact Availability (MVA): None (N)
-
Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
-
Modified Subsequent System Impact Integrity (MSI): Negligible (N)
-
Modified Subsequent System Impact Availability (MSA): Negligible (N)
-
Safety (S): Not Defined (X)
-
Automatable (AU): Not Defined (X)
-
Recovery (R): Not Defined (X)
-
Value Density (V): Not Defined (X)
-
Vulnerability Response Effort (RE): Not Defined (X)
-
Provider Urgency (U): Not Defined (X)
-
Confidentiality Req. (CR): Not Defined (X)
-
Integrity Req. (IR): Not Defined (X)
-
Availability Req. (AR): Not Defined (X)
-
Exploit Maturity (E): Not Defined (X)
updated
1 month, 2 weeks ago
by @LeSuisse
Activity log
-
Created suggestion
1 month, 2 weeks ago
-
@LeSuisse
ignored
reference https://g…
1 month, 2 weeks ago
-
@LeSuisse
ignored
maintainer @dotlambda
1 month, 2 weeks ago
maintainer.ignore
-
@LeSuisse
accepted
1 month, 2 weeks ago
-
@LeSuisse
published on GitHub
1 month, 2 weeks ago
bubblewrap vulnerable to privilege escalation in setuid mode via ptrace
updated
1 month, 2 weeks ago
by @LeSuisse
Activity log
-
Created suggestion
1 month, 2 weeks ago
-
@LeSuisse
ignored
reference https://g…
1 month, 2 weeks ago
-
@LeSuisse
accepted
1 month, 2 weeks ago
-
@LeSuisse
published on GitHub
1 month, 2 weeks ago
GitPython: Path traversal in GitPython reference APIs allows arbitrary file write and delete outside the repository
updated
1 month, 2 weeks ago
by @LeSuisse
Activity log
-
Created suggestion
1 month, 2 weeks ago
-
@LeSuisse
accepted
1 month, 2 weeks ago
-
@LeSuisse
published on GitHub
1 month, 2 weeks ago
BentoPDF: Stored XSS via Markdown Editor Leading to Persistent File Exfiltration
updated
1 month, 2 weeks ago
by @LeSuisse
Activity log
-
Created suggestion
1 month, 2 weeks ago
-
@LeSuisse
ignored
3 packages
- openexr_2
- openexrid-unstable
- haskellPackages.openexr-write
1 month, 2 weeks ago
-
@LeSuisse
accepted
1 month, 2 weeks ago
-
@LeSuisse
published on GitHub
1 month, 2 weeks ago
OpenEXR: Shift exponent overflow in `readVariableLengthInteger()` (`ImfIDManifest.cpp`)
openexr
-
==>= 3.0.0, < 3.2.9
-
==>= 3.4.0, < 3.4.11
-
==>= 3.3.0, < 3.3.11
updated
1 month, 2 weeks ago
by @LeSuisse
Activity log
-
Created suggestion
1 month, 2 weeks ago
-
@LeSuisse
ignored
3 packages
- openexr_2
- openexrid-unstable
- haskellPackages.openexr-write
1 month, 2 weeks ago
-
@LeSuisse
accepted
1 month, 2 weeks ago
-
@LeSuisse
published on GitHub
1 month, 2 weeks ago
OpenEXR: Out-of-bounds read in `IDManifest::init()` during prefix expansion
openexr
-
==>= 3.0.0, < 3.2.9
-
==>= 3.4.0, < 3.4.11
-
==>= 3.3.0, < 3.3.11
updated
1 month, 2 weeks ago
by @LeSuisse
Activity log
-
Created suggestion
1 month, 2 weeks ago
-
@LeSuisse
ignored
reference https://g…
1 month, 2 weeks ago
-
@LeSuisse
ignored
8 packages
- python313Packages.weblate-fonts
- python314Packages.weblate-fonts
- python312Packages.weblate-schemas
- python313Packages.weblate-schemas
- python314Packages.weblate-schemas
- python312Packages.weblate-language-data
- python313Packages.weblate-language-data
- python314Packages.weblate-language-data
1 month, 2 weeks ago
-
@LeSuisse
accepted
1 month, 2 weeks ago
-
@LeSuisse
published on GitHub
1 month, 2 weeks ago
Weblate is Vulnerable to Authenticated SSRF via Project Backup Import bypassing validate_repo_url