LOW3.1CVE-2026-47715Bugsink: Issue event views can show an event from another project if its UUID is known
LOW2.7CVE-2026-45723Omni: Operator can traverse image-factory API paths via unsanitized `talos_version` in CreateSchematic
LOW3.1Apache Airflow: DAG authorization bypass on /ui/structure/structure_data
LOW3.1Insufficient policy enforcement in Password Manager in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised t…
LOW3.1Insufficient policy enforcement in CustomTabs in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to leak cross-or…
LOW3.1Insufficient validation of untrusted input in WebAuthentication in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had c…
LOW3.1Insufficient validation of untrusted input in Loader in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised…
LOW3.7Shopware: Timing-attack on admin panel allowing enumeration of administrator usernames
LOW2.2In OpenStack Neutron before 28.0.1, a project manager can create or update a port on a shared network owned by another project and set devi…
LOW2.5A security flaw has been discovered in gradio-app gradio 6.14.0.
LOW3.7daphne before 4.2.2 reconstructs a raw HTTP request from Twisted's parsed headers and feeds it to autobahn for WebSocket handshake processi…
LOW3.1A flaw has been found in dask up to 3.0.
LOW3.3EPSS 0.01%A security flaw has been discovered in Orthanc DICOM Server up to 1.12.11.
LOW3.3EPSS 0.01%A security flaw has been discovered in ggml-org whisper.cpp up to 1.8.2.
LOW3.1EPSS 0.04%Apache Airflow: Log server JWT authorization bypass via Python lstrip() character stripping allows cross-Dag log access
LOW3.3EPSS 0.01%A security vulnerability has been detected in Assimp up to 6.0.4.
LOW3.3EPSS 0.01%A vulnerability was determined in Assimp up to 6.0.4.
LOW3.3EPSS 0.01%A vulnerability has been found in Assimp up to 6.0.4.
LOW3.3EPSS 0.01%A flaw has been found in Assimp up to 6.0.4.
LOW3.3EPSS 0.01%A vulnerability was detected in Assimp up to 6.0.4.
LOW3.7Axios has a Patch Bypass: Proxy-Authorization Header Injection via Prototype Pollution — Incomplete Null-Prototype Fix
LOW3.17-Zip is a file archiver with a high compression ratio.
LOW3.3Dulwich doesn't sanitize commit subjects in `porcelain.format_patch`
LOW3.1EPSS 0.03%Inappropriate implementation in Media in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote attacker who had compromised the…
LOW3.1EPSS 0.03%Race in WebRTC in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote attacker to leak cross-origin data via a crafted HTML p…