Watch
Security advisories
Vulnerabilities in the libraries, SDKs and tools you depend on — with the version that fixes them.
Follow this register via RSS- 148
- advisories logged
- 44
- in the last 7 days
- 109
- actively exploited
- 121
- rated critical
0 entries
Filter
Urgency
Severity
Ecosystem
Class
- NuGetMicrosoft.WindowsDesktop.App.Runtime.win-x64Unsafe deserialisation · >= 10.0.0, <= 10.0.9→ 10.0.10CVE-2026-50646
- PyPInltkPath traversal · >= 3.10.0, < 3.10.2→ 3.10.2CVE-2026-62384
- PyPInltkPath traversal · <= 3.9.4→ 3.10.0CVE-2026-62385
- NuGetMicrosoft.Native.Quic.MsQuic.OpenSSLRemote code execution · >= 2.5.3, < 2.5.10→ 2.5.10CVE-2026-62815
- npmliquidjsDenial of service · <= 10.27.1→ 10.27.2CVE-2026-69222
- PyPInltkPath traversal · <= 3.9.3→ 3.9.4CVE-2026-70626
- Gogithub.com/siyuan-note/siyuan/kernelAuthentication bypass · < 0.0.0-20260726020813-a25c2dd06aae→ 0.0.0-20260726020813-a25c2dd06aaeCVE-2026-72789
- Gogithub.com/semaphoreui/semaphoreRemote code execution · < 0.0.0-20260704181911-7e8a9434bd81→ 0.0.0-20260704181911-7e8a9434bd81CVE-2026-73294
- Mavenio.netty:netty-handlerOther · >= 4.2.0.Final, <= 4.2.16.Final→ 4.2.17.FinalCVE-2026-75595
- npmnextPath traversal · >= 13.4.0, < 15.5.24→ 15.5.24CVE-2026-75604
- SoftwareAdobe Commerce and MagentoActively exploitedRemote code executionNo fix publishedCVE-2026-75650
- npmmulterDenial of service · = 2.2.0→ 2.3.0CVE-2026-77037
- npmmulterDenial of service · < 2.3.0→ 2.3.0CVE-2026-77078
- Composercakephp/cakephpInjection · >= 5.3.0, < 5.3.7→ 5.3.7CVE-2026-77635
- PyPIGitPythonPath traversal · <= 3.1.58→ 3.1.59CVE-2026-78675
- PyPIGitPythonRemote code execution · <= 3.1.58→ 3.1.59CVE-2026-78676
- PyPIGitPythonPath traversal · <= 3.1.58→ 3.1.59CVE-2026-78677
- PyPInltkUnsafe deserialisation · <= 3.9.4→ 3.10.0CVE-2026-78683
- PyPInltkUnsafe deserialisation · <= 3.10.2→ 3.10.3CVE-2026-79657
- PyPInltkDenial of service · <= 3.9.4→ 3.10.0CVE-2026-80205
- Composermongodb/mongodbInjection · < 1.21.4→ 1.21.4CVE-2026-81525
- OSMicrosoft WindowsActively exploitedPath traversalNo fix publishedCVE-2026-81963
- npmmulterDenial of service · < 2.3.0→ 2.3.0CVE-2026-82333
- Composercomposer/composerRemote code execution · >= 2.3.0, < 2.10.3→ 2.10.3CVE-2026-84361
- npmsvgoCross-site scripting · >= 1.0.0, < 2.8.4→ 2.8.4CVE-2026-84370
- Composerpredis/predisRemote code execution · >= 3.0.0-RC1, < 3.3.0→ 3.3.0CVE-2026-84372
- Composermaatwebsite/excelPath traversal · >= 3.1.8, < 3.1.70→ 3.1.70CVE-2026-84374
- npmjs-yamlDenial of service · >= 4.0.0, < 4.3.2→ 4.3.2CVE-2026-84375
- PyPIhttpcore2Other · < 2.10.0→ 2.10.0CVE-2026-84381
- PyPIhttpx2Denial of service · < 2.12.0→ 2.12.0CVE-2026-84382
- Gogoogle.golang.org/grpcDenial of service · < 1.82.2→ 1.82.2CVE-2026-84445
- PyPIwinml-cliAuthentication bypass · < 0.4.0→ 0.4.0CVE-2026-84452
- npmmaplibre-glCross-site scripting · <= 6.4.0→ 6.4.1CVE-2026-85061
- OSMicrosoft WindowsActively exploitedOtherNo fix publishedCVE-2026-85880
- SoftwareN-able N-centralActively exploitedRemote code executionNo fix publishedCVE-2026-86218
- npmastroRemote code execution · < 7.2.8→ 7.2.8GHSA-26w7-cxv4-gfx2
- npm@typespec/openapi3Path traversal · <= 1.15.0No fix publishedGHSA-2q42-4q24-7rgv
- npmnodemailerDenial of service · < 9.1.0→ 9.1.0GHSA-2x7j-588g-ccc2
- npmnextRemote code execution · >= 10.0.0, < 15.5.24→ 15.5.24GHSA-2xp9-vwfh-vxw4
- npm@tiptap/coreDenial of service · >= 3.7.0, < 3.30.5→ 3.30.5GHSA-j95f-988m-3j2f
- NuGetMicrosoft.DiaSymReader.NativeRemote code execution · >= 17.10.0-beta1.24272.1, <= 18.9.0-beta1.26405.1→ 18.9.0-beta1.26405.2GHSA-q72m-f2r4-w4cw
- npmsharpRemote code execution · < 0.35.4→ 0.35.4GHSA-rgj7-g3m4-5g8c
- BrowserGoogle Chromium V8Actively exploitedRemote code executionNo fix publishedCVE-2026-85046
- npm@typespec/spectorAuthentication bypass · <= 0.1.0-alpha.26→ 0.1.0-alpha.27GHSA-7q9c-hpx7-9cwm
- SoftwareKludex StarletteActively exploitedAuthentication bypassNo fix publishedCVE-2026-48710
- SoftwareKestra OSSActively exploitedRemote code executionNo fix publishedCVE-2026-49869
- SoftwareBerriAI LiteLLMActively exploitedAuthentication bypassNo fix publishedCVE-2026-59822
- SoftwareJFrog ArtifactoryActively exploitedAuthentication bypassNo fix publishedCVE-2026-82329
- NetworkSonicWall SMA1000 AppliancesActively exploitedServer-side request forgeryNo fix publishedCVE-2026-83548
- NetworkSonicWall SMA1000 AppliancesActively exploitedRemote code executionNo fix publishedCVE-2026-83549
- SoftwareSangoma SwitchvoxActively exploitedInjectionNo fix publishedCVE-2026-9586
- SoftwarePaperCut NG/MFActively exploitedAuthentication bypassNo fix publishedCVE-2026-81578
- SoftwarePaperCut NG/MFActively exploitedRemote code executionNo fix publishedCVE-2026-82078
- SoftwareownCloudActively exploitedAuthentication bypassNo fix publishedCVE-2023-49105
- OSLinux KernelActively exploitedPrivilege escalationNo fix publishedCVE-2026-53362
- SoftwareJFrog ArtifactoryActively exploitedPath traversalNo fix publishedCVE-2026-66384
- OSRed Hat LibuserActively exploitedPrivilege escalationNo fix publishedCVE-2015-3246
- OSRed Hat Automatic Bug Reporting ToolActively exploitedPath traversalNo fix publishedCVE-2015-5287
- SoftwareMicrosoft SQL ServerActively exploitedRemote code executionNo fix publishedCVE-2019-1068
- SoftwareAjax.NET ProfessionalActively exploitedUnsafe deserialisationNo fix publishedCVE-2021-23758
- OSLinux KernelActively exploitedDenial of serviceNo fix publishedCVE-2022-0995
- NetworkCitrix NetScaler ADC and NetScaler GatewayActively exploitedDenial of serviceNo fix publishedCVE-2026-8452
- SoftwareGiteaActively exploitedRemote code executionNo fix publishedCVE-2026-60004
- SoftwareOracle HTTP Server and Oracle Weblogic Server Proxy Plug-inActively exploitedAuthentication bypassNo fix publishedCVE-2026-21962
- SoftwareSynacor Zimbra Collaboration Suite (ZCS)Actively exploitedRemote code executionNo fix publishedCVE-2026-73570
- SoftwareTrueConf ServerActively exploitedAuthentication bypassNo fix publishedCVE-2026-72529
- SoftwareTrueConf ServerActively exploitedRemote code executionNo fix publishedCVE-2026-72530
- SoftwareMLflowActively exploitedServer-side request forgeryNo fix publishedCVE-2026-64849
- SoftwareMicrosoft Internet Key Exchange (IKE) Service ExtensionsActively exploitedRemote code executionNo fix publishedCVE-2026-33824
- SoftwareMicrosoft SharePointActively exploitedAuthentication bypassNo fix publishedCVE-2026-55040
- SoftwareBroadcom VMware vCenterActively exploitedPath traversalNo fix publishedCVE-2026-59310
- OSApple macOSActively exploitedAuthentication bypassNo fix publishedCVE-2026-65400
- BrowserRay-Project RayActively exploitedRemote code executionNo fix publishedCVE-2025-62593
- NetworkCisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD)Actively exploitedDenial of serviceNo fix publishedCVE-2026-20349
- OSMicrosoft Windows Ancillary Function Driver for WinSockActively exploitedOtherNo fix publishedCVE-2026-68820
- SoftwareMetabaseActively exploitedInjectionNo fix publishedCVE-2026-72898
- SoftwareProgress LoadMasterActively exploitedRemote code executionNo fix publishedCVE-2026-8037
- SoftwareJetBrains TeamCityActively exploitedUnsafe deserialisationNo fix publishedCVE-2026-63077
- SoftwareN-able N-centralActively exploitedAuthentication bypassNo fix publishedCVE-2026-18556
- SoftwareApache TomcatActively exploitedOtherNo fix publishedCVE-2026-34486
- SoftwareIBM LangflowActively exploitedRemote code executionNo fix publishedCVE-2026-9198
- SoftwareN-able N-centralActively exploitedAuthentication bypassNo fix publishedCVE-2026-18577
- NetworkCisco Secure Firewall Management Center (FMC)Actively exploitedOtherNo fix publishedCVE-2026-20316
- NetworkFortinet FortiOSActively exploitedInformation disclosureNo fix publishedCVE-2025-68686
- SoftwareArista VeloCloud OrchestratorActively exploitedRemote code executionNo fix publishedCVE-2026-16812
- SoftwareCheck Point SmartConsoleActively exploitedAuthentication bypassNo fix publishedCVE-2026-16232
- SoftwareMicrosoft SharePointActively exploitedUnsafe deserialisationNo fix publishedCVE-2026-50522
- SoftwareDD-WRTActively exploitedOtherNo fix publishedCVE-2021-27137
- SoftwareLangflowActively exploitedSupply chainNo fix publishedCVE-2026-0770
- SoftwareWordPress CoreActively exploitedInjectionNo fix publishedCVE-2026-60137
- SoftwareWordPress CoreActively exploitedRemote code executionNo fix publishedCVE-2026-63030
- NetworkFortinet FortiSandboxActively exploitedRemote code executionNo fix publishedCVE-2026-25089
- NetworkFortinet FortiSandboxActively exploitedRemote code executionNo fix publishedCVE-2026-39808
- SoftwareMicrosoft SharePointActively exploitedUnsafe deserialisationNo fix publishedCVE-2026-58644
- SoftwareKNX Association KNX Protocol Connection Authorization Option 1Actively exploitedOtherNo fix publishedCVE-2023-4346
- SoftwareOracle E-Business SuiteActively exploitedAuthentication bypassNo fix publishedCVE-2026-46817
- NetworkSonicWall SMA1000 AppliancesActively exploitedServer-side request forgeryNo fix publishedCVE-2026-15409
- NetworkSonicWall SMA1000 AppliancesActively exploitedRemote code executionNo fix publishedCVE-2026-15410
- SoftwareMicrosoft Active Directory Federation ServicesActively exploitedAuthentication bypassNo fix publishedCVE-2026-56155
- SoftwareMicrosoft SharePoint ServerActively exploitedAuthentication bypassNo fix publishedCVE-2026-56164
- OSCisco IOSActively exploitedOtherNo fix publishedCVE-2008-4128
- SoftwareiCagendaActively exploitedOtherNo fix publishedCVE-2026-48939
- SoftwareBalbooa FormsActively exploitedRemote code executionNo fix publishedCVE-2026-56291
- SoftwareAdobe ColdFusionActively exploitedPath traversalNo fix publishedCVE-2026-48282
- SoftwareJoomShaper SP Page BuilderActively exploitedOtherNo fix publishedCVE-2026-48908
- SoftwareLangflowActively exploitedAuthentication bypassNo fix publishedCVE-2026-55255
- SoftwareJoomlack Page BuilderActively exploitedRemote code executionNo fix publishedCVE-2026-56290
- SoftwareMicrosoft SharePoint ServerActively exploitedUnsafe deserialisationNo fix publishedCVE-2026-45659
- SoftwareSimpleHelpActively exploitedCryptographic weaknessNo fix publishedCVE-2026-48558
- SoftwarePTC Windchill and FlexPLMActively exploitedUnsafe deserialisationNo fix publishedCVE-2026-12569
- NetworkCisco Unified Communications ManagerActively exploitedServer-side request forgeryNo fix publishedCVE-2026-20230
- SoftwareLantronix EDS5000Actively exploitedRemote code executionNo fix publishedCVE-2025-67038
- SoftwareUbiquiti UniFi OSActively exploitedAuthentication bypassNo fix publishedCVE-2026-34908
- SoftwareUbiquiti UniFi OSActively exploitedPath traversalNo fix publishedCVE-2026-34909
- SoftwareUbiquiti UniFi OSActively exploitedRemote code executionNo fix publishedCVE-2026-34910
- SoftwareSplunk EnterpriseActively exploitedAuthentication bypassNo fix publishedCVE-2026-20253
- SoftwareWidget Factory Joomla Content EditorActively exploitedAuthentication bypassNo fix publishedCVE-2026-48907
- NetworkCisco Catalyst SD-WAN ManagerActively exploitedPath traversalNo fix publishedCVE-2026-20262
- OSLiteSpeed cPanel PluginActively exploitedPath traversalNo fix publishedCVE-2026-54420
- SoftwareOracle PeopleSoft Enterprise PeopleToolsActively exploitedAuthentication bypassNo fix publishedCVE-2026-35273
- NetworkIvanti SentryActively exploitedRemote code executionNo fix publishedCVE-2026-10520
- BrowserGoogle Chromium V8Actively exploitedRemote code executionNo fix publishedCVE-2026-11645
- NetworkCisco Catalyst SD-WAN ManagerActively exploitedOtherNo fix publishedCVE-2026-20245
- SoftwareArista Extensible Operating SystemActively exploitedOtherNo fix publishedCVE-2026-7473
- SoftwareBerriAI LiteLLMActively exploitedRemote code executionNo fix publishedCVE-2026-42271
- NetworkCheck Point Security GatewayActively exploitedAuthentication bypassNo fix publishedCVE-2026-50751
- SoftwareSolarWinds Serv-UActively exploitedDenial of serviceNo fix publishedCVE-2026-28318
- SoftwareMirasvit Full Page Cache WarmerActively exploitedUnsafe deserialisationNo fix publishedCVE-2026-45247
- OSLinux KernelActively exploitedAuthentication bypassNo fix publishedCVE-2022-0492
- OSAndroid FrameworkActively exploitedPrivilege escalationNo fix publishedCVE-2025-48595
- SoftwareOracle WebLogic ServerActively exploitedOtherNo fix publishedCVE-2024-21182
- NetworkPalo Alto Networks PAN-OSActively exploitedAuthentication bypassNo fix publishedCVE-2026-0257
- SoftwareTanStackActively exploitedOtherNo fix publishedCVE-2026-45321
- SoftwareNx ConsoleActively exploitedSupply chainNo fix publishedCVE-2026-48027
- SoftwareDaemon Tools LiteActively exploitedSupply chainNo fix publishedCVE-2026-8398
- SoftwareLiteSpeed cPanel PluginActively exploitedPrivilege escalationNo fix publishedCVE-2026-48172
- SoftwareDrupal CoreActively exploitedInjectionNo fix publishedCVE-2026-9082
- SoftwareLangflowActively exploitedRemote code executionNo fix publishedCVE-2025-34291
- SoftwareTrend Micro Apex OneActively exploitedPath traversalNo fix publishedCVE-2026-34926
- OSMicrosoft WindowsActively exploitedRemote code executionNo fix publishedCVE-2008-4250
- SoftwareMicrosoft DirectXActively exploitedRemote code executionNo fix publishedCVE-2009-1537
- SoftwareAdobe Acrobat and ReaderActively exploitedRemote code executionNo fix publishedCVE-2009-3459
- SoftwareMicrosoft Internet ExplorerActively exploitedRemote code executionNo fix publishedCVE-2010-0249
- SoftwareMicrosoft Internet ExplorerActively exploitedRemote code executionNo fix publishedCVE-2010-0806
- SoftwareMicrosoft DefenderActively exploitedPath traversalNo fix publishedCVE-2026-41091
- SoftwareMicrosoft DefenderActively exploitedDenial of serviceNo fix publishedCVE-2026-45498
- SoftwareMicrosoftActively exploitedCross-site scriptingNo fix publishedCVE-2026-42897
- NetworkCisco Catalyst SD-WANActively exploitedAuthentication bypassNo fix publishedCVE-2026-20182
No entry matches these filters.
How this register is built
Every morning the register pulls GitHub Security Advisories — reviewed by their security team, rated high or critical, and naming an actual package — along with CISA’s Known Exploited Vulnerabilities catalog.
No entry is written by a model: ecosystem, affected versions, fixed version and score come straight from the cited advisory. Rewriting a version number would only add a chance of error to the one field you are going to copy.
A flaw listed by CISA is marked “actively exploited” and rated critical regardless of its score: a score measures potential, observed exploitation measures a fact.