CRITICAL9.0CVE-2026-55203HAProxy through 3.4.0, fixed in commit 5985276, contains an integer overflow vulnerability in the fcgi_conn structure's drl field that allo…
MEDIUM5.3A flaw in Node.js HTTP/2 server API can cause servers to keep accepting data even after sending a `GOAWAY` frame.
MEDIUM6.5NL Portal Backend Libraries: Document contents remained downloadable by any logged-in user (incomplete fix of CVE-2026-49463)
MEDIUM6.5BBOT: Arbitrary File Write in postman_download Module
MEDIUM5.3BBOT: Path traversal (Zip-Slip) in unarchive module - incomplete fix for CVE-2025-10284
MEDIUM5.4Strimzi: Unrestricted access to all Secrets within namespace watched by the Topic operator
MEDIUM6.1marimo contains a reflected cross-site scripting vulnerability in the notebook page
MEDIUM5.3joserfc is a Python library that provides an implementation of several JSON Object Signing and Encryption (JOSE) standards.
MEDIUM5.9Impact: undici's cookie parser in parseSetCookie percent-decodes cookie values via qsUnescape, turning encoded sequences like %0D%0A, %00,…
MEDIUM5.9undici vulnerable to cross-user information disclosure via shared cache whitespace bypass
MEDIUM5.8Shaarli is a personal bookmarking service.
MEDIUM5.9libssh2 through 1.11.1, fixed in commit 1762685, contains a pre-authentication denial of service vulnerability in the SSH_MSG_EXT_INFO hand…
CRITICAL9.1Tinyproxy through 1.11.3, fixed in commit 364cdb6, fails to reject requests containing multiple Content-Length headers with differing value…
CRITICAL9.1Tinyproxy through 1.11.3, fixed in commit ff45d3b, fails to reconcile conflicting Content-Length and Transfer-Encoding: chunked headers, fo…
MEDIUM4.8Shaarli is a personal bookmarking service.
MEDIUM5.8Shaarli is a personal bookmarking service.
MEDIUM6.0OpenStack Horizon RC file generation does not escape special characters in project names
CRITICAL9.3Langflow: Unauthenticated file upload leads to DoS (space exhaustion) and information leak
CRITICAL9.1Apache Airflow SFTP provider: Path traversal in SFTPHook.retrieve_directory
MEDIUM6.5Apache DolphinScheduler: An incorrect authorization vulnerability allows authenticated users to access alert instances associated with alert groups they do not have permission to access.
MEDIUM6.5Apache DolphinScheduler: Incorrect Authorization vulnerability allows users to access workflow instance information belonging to projects they do not have permission to access.
MEDIUM4.9Apache DolphinScheduler: Incorrect Authorization vulnerability allows users with system login privileges to delete task definitions in unauthorized projects
CRITICAL9.1Apache DolphinScheduler: The `/v2` experimental interface lacks permission checks
CRITICAL9.8Apache DolphinScheduler: DataSource API Missing Authorization Check Leads to Arbitrary Data Source Metadata Disclosure