MEDIUM6.5libheif is a HEIF and AVIF file format decoder and encoder.
MEDIUM6.5UltraJSON: Malformed/Truncated UTF-8 Accepted and Silently Rewritten in ujson.dumps()
MEDIUM5.8guzzlehttp/guzzle: Dot-Only Cookie Domains Match All Hosts
MEDIUM5.9guzzlehttp/guzzle: Silent HTTPS-Proxy Downgrade to Cleartext
MEDIUM5.3NL Portal Backend Libraries: Unauthenticated form resolver forwards the privileged Objecten-API token to a caller-supplied URL (SSRF)
HIGH8.3libssh2 through 1.11.1, fixed in commit 2dae302, contains an out-of-bounds heap read vulnerability in the sftp_symlink() function in src/sf…
CRITICAL9.9Network-AI: Improper Neutralization of Special Elements used in an OS Command
CRITICAL9.1Network-AI: CVE-2026-46701 fix incomplete — empty default secret still authorizes all requests
MEDIUM6.5A path traversal in handling the "path" component of .repo files processed by libzypp before 17.38.13 in the 17.x series, or before 16.22.1…
MEDIUM6.1OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry.
MEDIUM5.4Coturn is a free open source implementation of TURN and STUN Server.
MEDIUM4.9libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_ResumeParser from within handlers in cases of a policy violation.
MEDIUM4.8guzzlehttp/psr7: CRLF Injection in HTTP Start-Line Serialization
MEDIUM5.3ts-deepmerge: Prototype Method Override leads to DoS
CRITICAL9.0HAProxy through 3.4.0, fixed in commit 5985276, contains an integer overflow vulnerability in the fcgi_conn structure's drl field that allo…