VulnScope — package-centric CVE lookup- —CVE-2026-54604
- MEDIUM5.3CVE-2026-49342YARD is a documentation generation tool for the Ruby programming language.
- HIGH7.1libde265 is an open source implementation of the h.265 video codec.
- MEDIUM4.3libde265 is an open source implementation of the h.265 video codec.
- HIGH7.1libde265 is an open source implementation of the h.265 video codec.
- —Crypt::OpenSSL::PKCS12 versions before 1.96 for Perl permits a heap OOB read in print_attribute UTF8STRING path.
- —urllib3 version 2.6.3 is vulnerable to a decompression bomb bypass in its streaming API (`preload_content=False`) when using Brotli support.
- MEDIUM6.5A use-after-free vulnerability was found in FFmpeg's RASC video decoder.
- MEDIUM4.4Outerbase Studio: Stored XSS in Text Widget Leads to Authentication Token Exposure
- MEDIUM6.1Allure Report: Stored XSS via unescaped ANSI helper in status message/trace rendering
- MEDIUM6.2Allure Report: Path Traversal in HTTP Server Allows Arbitrary File Read
- —TinaCMS: Cross-origin postMessage handlers and rich-text URL-sanitization bypass enable stored XSS and session takeover
- HIGH7.8@tinacms/cli: Remote Code Execution in @tinacms/cli via Forestry migration — unsanitised __TINA_INTERNAL__ marker in user-controlled YAML labels
- HIGH7.1A remote code execution vulnerability was found in libaom, the reference AV1 codec implementation.
- HIGH7.6A heap buffer overflow vulnerability was found in libaom, the reference AV1 codec implementation.
- HIGH7.1An arbitrary address write vulnerability was found in libaom, the reference AV1 codec implementation.
- HIGH7.1A heap-buffer-overflow read vulnerability was found in libaom, the reference AV1 codec implementation.
- MEDIUM6.5libheif is a HEIF and AVIF file format decoder and encoder.
- HIGH7.5flat-to-nested: Prototype pollution in flat-to-nested convert() via __proto__ parent/id key
- —@cyclonedx/cyclonedx-npm: Shell Injection via Unsanitized --workspace Argument
- —parse-server: Stored XSS via non-standard file extension bypassing file upload extension blocklist
- —jupyterlab-git extension: Stored XSS leading to RCE
- —containerd CRI checkpoint restore CDI annotation smuggling
- —Arbitrary host CRI log file read via symlink following in CRI checkpoint restore
- —containerd CRI — image-config `LABEL` flows to restart-monitor `binary://` logger: host-root command execution from an image pull