HIGH8.1CVE-2026-44249Netty has an IPv6 Subnet Filter Bypass via Incorrect Comparator Masking
HIGH8.7TinyMCE Cross-Site Scripting (XSS) vulnerability using media plugin `data-mce-object` injection
HIGH8.7TinyMCE Cross-Site Scripting (XSS) vulnerability through `mce:protected` comments
HIGH8.7TinyMCE Cross-Site Scripting (XSS) vulnerability using through data-mce- prefixed src, href, style attributes
HIGH8.7TinyMCE Cross-Site Scripting (XSS) vulnerability using sanitization bypass through nested SVGs
CRITICAL9.1NASA AMMOS Instrument Toolkit: Path traversal resulting in arbitrary file append (can be triggered over the network by unauthenticated attacker)
HIGH8.8DbGate: Remote Code Execution via functionName injection in loadReader endpoint
HIGH7.7Sync-in Server: SSRF protection bypass via IPv4-mapped IPv6 addresses in regExpPrivateIP
HIGH8.3praisonai-platform: Agent endpoints accept any agent_id without workspace ownership check, cross-workspace read/update/delete IDOR
CRITICAL10.0DbGate: Unauthenticated Remote Code Execution via JSON Script Runner
HIGH7.3Apache Airflow: Arbitrary import in custom deadline-reference deserialization