Published issues
WordPress ProfilePress plugin <= 4.16.13 - Cross Site Scripting (XSS) vulnerability
Permalink
CVE-2026-41556
6.5 MEDIUM
-
CVSS version (CVSS): 3.1
-
Attack Vector (AV): Network (N)
-
Attack Complexity (AC): Low (L)
-
Privileges Required (PR): Low (L)
-
User Interaction (UI): Required (R)
-
Scope (S): Changed (C)
-
Confidentiality (C): Low (L)
-
Integrity (I): Low (L)
-
Availability (A): Low (L)
-
Modified Attack Vector (MAV): Network (N)
-
Modified Attack Complexity (MAC): Low (L)
-
Modified Privileges Required (MPR): Low (L)
-
Modified User Interaction (MUI): Required (R)
-
Modified Confidentiality (MC): Low (L)
-
Modified Scope (MS): Changed (C)
-
Modified Integrity (MI): Low (L)
-
Modified Availability (MA): Low (L)
updated
2 months, 4 weeks ago
by @LeSuisse
Activity log
-
Created suggestion
2 months, 4 weeks ago
-
@LeSuisse
accepted
2 months, 4 weeks ago
-
@LeSuisse
published on GitHub
2 months, 4 weeks ago
WordPress ProfilePress plugin <= 4.16.13 - Cross Site Scripting (XSS) vulnerability
svaarala duktape duk_api_bytecode.c memory corruption
Gnutls: fix use-after-free in gnutls_pkcs11_token_set_pin
Permalink
CVE-2026-42014
6.6 MEDIUM
-
CVSS version (CVSS): 3.1
-
Attack Vector (AV): Local (L)
-
Attack Complexity (AC): Low (L)
-
Privileges Required (PR): Low (L)
-
User Interaction (UI): None (N)
-
Scope (S): Unchanged (U)
-
Confidentiality (C): Low (L)
-
Integrity (I): Low (L)
-
Availability (A): High (H)
-
Modified Attack Vector (MAV): Local (L)
-
Modified Attack Complexity (MAC): Low (L)
-
Modified Privileges Required (MPR): Low (L)
-
Modified User Interaction (MUI): None (N)
-
Modified Confidentiality (MC): Low (L)
-
Modified Scope (MS): Unchanged (U)
-
Modified Integrity (MI): Low (L)
-
Modified Availability (MA): High (H)
updated
2 months, 4 weeks ago
by @LeSuisse
Activity log
-
Created suggestion
2 months, 4 weeks ago
-
@LeSuisse
ignored
3 packages
- guile-gnutls
- python313Packages.python3-gnutls
- python314Packages.python3-gnutls
2 months, 4 weeks ago
-
@LeSuisse
ignored
maintainer @vcunat
2 months, 4 weeks ago
maintainer.ignore
-
@LeSuisse
accepted
2 months, 4 weeks ago
-
@LeSuisse
published on GitHub
2 months, 4 weeks ago
Gnutls: fix use-after-free in gnutls_pkcs11_token_set_pin
rhcos
gnutls
rhui5/cds-rhel9
rhui5/rhua-rhel9
rhui5/haproxy-rhel9
rhui5/installer-rhel9
FileBrowser Quantum: Path Traversal in public share PATCH allows file ops outside shared directory
Permalink
CVE-2026-48777
9.3 CRITICAL
-
CVSS version (CVSS): 4.0
-
Attack Vector (AV): Network (N)
-
Attack Complexity (AC): Low (L)
-
Attack Requirement (AT): None (N)
-
Privileges Required (PR): None (N)
-
User Interaction (UI): None (N)
-
Vulnerable System Impact Confidentiality (VC): High (H)
-
Vulnerable System Impact Integrity (VI): High (H)
-
Vulnerable System Impact Availability (VA): None (N)
-
Subsequent System Impact Confidentiality (SC): None (N)
-
Subsequent System Impact Integrity (SI): None (N)
-
Subsequent System Impact Availability (SA): None (N)
-
Modified Attack Vector (MAV): Network (N)
-
Modified Attack Complexity (MAC): Low (L)
-
Modified Attack Requirement (MAT): None (N)
-
Modified Privileges Required (MPR): None (N)
-
Modified User Interaction (MUI): None (N)
-
Modified Vulnerable System Impact Confidentiality (MVC): High (H)
-
Modified Vulnerable System Impact Integrity (MVI): High (H)
-
Modified Vulnerable System Impact Availability (MVA): None (N)
-
Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
-
Modified Subsequent System Impact Integrity (MSI): Negligible (N)
-
Modified Subsequent System Impact Availability (MSA): Negligible (N)
-
Safety (S): Not Defined (X)
-
Automatable (AU): Not Defined (X)
-
Recovery (R): Not Defined (X)
-
Value Density (V): Not Defined (X)
-
Vulnerability Response Effort (RE): Not Defined (X)
-
Provider Urgency (U): Not Defined (X)
-
Confidentiality Req. (CR): Not Defined (X)
-
Integrity Req. (IR): Not Defined (X)
-
Availability Req. (AR): Not Defined (X)
-
Exploit Maturity (E): Not Defined (X)
updated
2 months, 4 weeks ago
by @LeSuisse
Activity log
-
Created suggestion
2 months, 4 weeks ago
-
@LeSuisse
ignored
3 packages
- filebrowser
- python313Packages.filebrowser-safe
- python314Packages.filebrowser-safe
2 months, 4 weeks ago
-
@LeSuisse
ignored
2 maintainers
2 months, 4 weeks ago
maintainer.ignore
-
@LeSuisse
accepted
2 months, 4 weeks ago
-
@LeSuisse
published on GitHub
2 months, 4 weeks ago
FileBrowser Quantum: Path Traversal in public share PATCH allows file ops outside shared directory
filebrowser
-
==>= 1.4.0-beta, < 1.4.2-beta
-
==< 1.3.3-stable
OliveTin: ValidateArgumentType API Endpoint Missing Authentication Allows Action and Argument Enumeration
Permalink
CVE-2026-48709
3.7 LOW
-
CVSS version (CVSS): 3.1
-
Attack Vector (AV): Network (N)
-
Attack Complexity (AC): High (H)
-
Privileges Required (PR): None (N)
-
User Interaction (UI): None (N)
-
Scope (S): Unchanged (U)
-
Confidentiality (C): Low (L)
-
Integrity (I): None (N)
-
Availability (A): None (N)
-
Modified Attack Vector (MAV): Network (N)
-
Modified Attack Complexity (MAC): High (H)
-
Modified Privileges Required (MPR): None (N)
-
Modified User Interaction (MUI): None (N)
-
Modified Confidentiality (MC): Low (L)
-
Modified Scope (MS): Unchanged (U)
-
Modified Integrity (MI): None (N)
-
Modified Availability (MA): None (N)
updated
2 months, 4 weeks ago
by @LeSuisse
Activity log
-
Created suggestion
2 months, 4 weeks ago
-
@LeSuisse
accepted
2 months, 4 weeks ago
-
@LeSuisse
published on GitHub
2 months, 4 weeks ago
OliveTin: ValidateArgumentType API Endpoint Missing Authentication Allows Action and Argument Enumeration
OliveTin has a Concurrent Template Parsing Race Condition which Leads to Cross-Request Command Contamination
Permalink
CVE-2026-48708
7.5 HIGH
-
CVSS version (CVSS): 3.1
-
Attack Vector (AV): Network (N)
-
Attack Complexity (AC): High (H)
-
Privileges Required (PR): Low (L)
-
User Interaction (UI): None (N)
-
Scope (S): Unchanged (U)
-
Confidentiality (C): High (H)
-
Integrity (I): High (H)
-
Availability (A): High (H)
-
Modified Attack Vector (MAV): Network (N)
-
Modified Attack Complexity (MAC): High (H)
-
Modified Privileges Required (MPR): Low (L)
-
Modified User Interaction (MUI): None (N)
-
Modified Confidentiality (MC): High (H)
-
Modified Scope (MS): Unchanged (U)
-
Modified Integrity (MI): High (H)
-
Modified Availability (MA): High (H)
updated
2 months, 4 weeks ago
by @LeSuisse
Activity log
-
Created suggestion
2 months, 4 weeks ago
-
@LeSuisse
accepted
2 months, 4 weeks ago
-
@LeSuisse
published on GitHub
2 months, 4 weeks ago
OliveTin has a Concurrent Template Parsing Race Condition which Leads to Cross-Request Command Contamination
Valhalla has reflected XSS via unsanitized JSONP callback parameter
Permalink
CVE-2026-49294
6.1 MEDIUM
-
CVSS version (CVSS): 3.1
-
Attack Vector (AV): Network (N)
-
Attack Complexity (AC): Low (L)
-
Privileges Required (PR): None (N)
-
User Interaction (UI): Required (R)
-
Scope (S): Changed (C)
-
Confidentiality (C): Low (L)
-
Integrity (I): Low (L)
-
Availability (A): None (N)
-
Modified Attack Vector (MAV): Network (N)
-
Modified Attack Complexity (MAC): Low (L)
-
Modified Privileges Required (MPR): None (N)
-
Modified User Interaction (MUI): Required (R)
-
Modified Confidentiality (MC): Low (L)
-
Modified Scope (MS): Changed (C)
-
Modified Integrity (MI): Low (L)
-
Modified Availability (MA): None (N)
updated
2 months, 4 weeks ago
by @LeSuisse
Activity log
-
Created suggestion
2 months, 4 weeks ago
-
@LeSuisse
accepted
2 months, 4 weeks ago
-
@LeSuisse
published on GitHub
2 months, 4 weeks ago
Valhalla has reflected XSS via unsanitized JSONP callback parameter
DbGate: Remote Code Execution via functionName injection in loadReader endpoint
Permalink
CVE-2026-48017
8.8 HIGH
-
CVSS version (CVSS): 3.1
-
Attack Vector (AV): Network (N)
-
Attack Complexity (AC): Low (L)
-
Privileges Required (PR): Low (L)
-
User Interaction (UI): None (N)
-
Scope (S): Unchanged (U)
-
Confidentiality (C): High (H)
-
Integrity (I): High (H)
-
Availability (A): High (H)
-
Modified Attack Vector (MAV): Network (N)
-
Modified Attack Complexity (MAC): Low (L)
-
Modified Privileges Required (MPR): Low (L)
-
Modified User Interaction (MUI): None (N)
-
Modified Confidentiality (MC): High (H)
-
Modified Scope (MS): Unchanged (U)
-
Modified Integrity (MI): High (H)
-
Modified Availability (MA): High (H)
updated
2 months, 4 weeks ago
by @LeSuisse
Activity log
-
Created suggestion
2 months, 4 weeks ago
-
@LeSuisse
accepted
2 months, 4 weeks ago
-
@LeSuisse
published on GitHub
2 months, 4 weeks ago
DbGate: Remote Code Execution via functionName injection in loadReader endpoint
WordPress ManageWP Worker plugin <= 4.9.31 - Cross Site Scripting (XSS) vulnerability
Permalink
CVE-2026-39463
7.1 HIGH
-
CVSS version (CVSS): 3.1
-
Attack Vector (AV): Network (N)
-
Attack Complexity (AC): Low (L)
-
Privileges Required (PR): None (N)
-
User Interaction (UI): Required (R)
-
Scope (S): Changed (C)
-
Confidentiality (C): Low (L)
-
Integrity (I): Low (L)
-
Availability (A): Low (L)
-
Modified Attack Vector (MAV): Network (N)
-
Modified Attack Complexity (MAC): Low (L)
-
Modified Privileges Required (MPR): None (N)
-
Modified User Interaction (MUI): Required (R)
-
Modified Confidentiality (MC): Low (L)
-
Modified Scope (MS): Changed (C)
-
Modified Integrity (MI): Low (L)
-
Modified Availability (MA): Low (L)
updated
2 months, 4 weeks ago
by @LeSuisse
Activity log
-
Created suggestion
2 months, 4 weeks ago
-
@LeSuisse
ignored
8 packages
- python314Packages.uvicorn-worker
- python313Packages.uvicorn-worker
- buildbotPackages.buildbot-worker
- haskellPackages.orderly-workers
- haskellPackages.Spock-worker
- buildbot-worker
- worker
- worker-build
2 months, 4 weeks ago
-
@LeSuisse
accepted
2 months, 4 weeks ago
-
@LeSuisse
published on GitHub
2 months, 4 weeks ago
WordPress ManageWP Worker plugin <= 4.9.31 - Cross Site Scripting (XSS) vulnerability
Crypt::DSA versions before 1.21 for Perl reused the nonce across signatures, leading to private-key recovery
updated
2 months, 4 weeks ago
by @LeSuisse
Activity log
-
Created suggestion
2 months, 4 weeks ago
-
@LeSuisse
accepted
2 months, 4 weeks ago
-
@LeSuisse
published on GitHub
2 months, 4 weeks ago
Crypt::DSA versions before 1.21 for Perl reused the nonce across signatures, leading to private-key recovery