MEDIUM6.9CVE-2026-50560Netty is a network application framework for development of protocol servers and clients.
MEDIUM4.8Netty is a network application framework for development of protocol servers and clients.
MEDIUM5.3Netty is a network application framework for development of protocol servers and clients.
MEDIUM6.7A flaw was found in QEMU's virtio-blk device.
MEDIUM5.3OpenTelemetry-cpp is the C++ implementation of OpenTelemetry.
MEDIUM5.4Fabric.js improper escaping in fabric.Gradient colorStops leads to XSS in SVG serialization
MEDIUM5.3Crypt::PBKDF2 versions before 0.261630 for Perl have a weak default algorithm and number of iterations.
MEDIUM5.9Crypt::PBKDF2 versions before 0.261630 for Perl are vulnerable to timing attacks.
CRITICAL9.0Budibase: Workspace-scoped builder escalates to global admin via /api/public/v1/roles/assign
MEDIUM6.5Budibase: Unanchored Regex in `matchers.ts` Allows CSRF Bypass via Query String Injection in Budibase Worker
MEDIUM6.7LangGraph has NoSQL parameter injection in MongoDBSaver, allowing cross-tenant state access
MEDIUM6.5A stack buffer overflow flaw was found in the GStreamer H.265 codec parser library (gst-plugins-bad).
MEDIUM5.3Out of bounds read in VideoCapture in Google Chrome prior to 149.0.7827.115 allowed a remote attacker who had compromised the GPU process t…
CRITICAL9.6Inappropriate implementation in Headless in Google Chrome prior to 149.0.7827.115 allowed a remote attacker who had compromised the rendere…
MEDIUM5.3Insufficient validation of untrusted input in Network in Google Chrome prior to 149.0.7827.115 allowed a remote attacker who had compromise…
MEDIUM6.5Insufficient policy enforcement in DevTools in Google Chrome prior to 149.0.7827.115 allowed a remote attacker to bypass same origin policy…
MEDIUM5.3Use after free in Autofill in Google Chrome prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process to o…
MEDIUM5.1Vim is an open source, command line text editor.
MEDIUM6.9Vim is an open source, command line text editor.
MEDIUM5.3Russh: SSH identification parsing accepted non-canonical client banners and did not bound pre-banner input
MEDIUM6.5Russh: Unchecked keyboard-interactive prompt count in client auth path
MEDIUM6.5An out-of-bounds write vulnerability was found in GStreamer's H.266/VVC PPS picture partition parser in gst-plugins-bad.
MEDIUM5.3@hapi/inert has a static-file confinement bypass via sibling-prefix path
MEDIUM5.3netty-codec-http2: ByteBuf Reference-Count Leak in DelegatingDecompressorFrameListener Leads to Memory Exhaustion
MEDIUM5.3joi has an uncaught RangeError on deeply nested input through recursive `link()` schemas