FLAT-DLZBS (GHSA-957r-qf9p-67xw)
Lack of data validation In craftcms/cms
4.6
Medium
Ecosystem: Packagist
Component: craftcms/cms
FLAT-VHDBT (CVE-2026-71554)
HTTP request smuggling In h2
1.7
Low
Ecosystem: PyPI
Component: h2
FLAT-5PRLL (GHSA-596p-6jv8-775v)
Sensitive information sent insecurely In craftcms/cms
1.2
Low
Ecosystem: Packagist
Component: craftcms/cms
FLAT-I3PX7 (GHSA-xxpx-f366-4xpq)
Improper authorization control for web services In craftcms/cms
1.3
Low
Ecosystem: Packagist
Component: craftcms/cms
FLAT-FOUHY (GHSA-rvmm-v933-jgxq)
Improper authorization control for web services In craftcms/cms
1.3
Low
Ecosystem: Packagist
Component: craftcms/cms
FLAT-AJ588 (GHSA-7hxc-f267-h5q7)
Lack of data validation - Path Traversal In craftcms/cms
0.5
Low
Ecosystem: Packagist
Component: craftcms/cms
FLAT-7XIWX (GHSA-2rp4-x2j7-qmcc)
Server side cross-site scripting In craftcms/cms
1.2
Low
Ecosystem: Packagist
Component: craftcms/cms
FLAT-DJQF5 (CVE-2026-67434)
OS Command Injection In squizlabs/php_codesniffer
4.4
Medium
Ecosystem: Packagist
Component: squizlabs/php_codesniffer
FLAT-2FLWD (CVE-2026-71498)
Out-of-bounds read In re2
0.5
Low
Ecosystem: Npm
Component: re2
FLAT-ARTTK (CVE-2026-71430)
Asymmetric denial of service In re2
4.6
Medium
Ecosystem: Npm
Component: re2
FLAT-0BNZA (GHSA-w9hm-4m3m-fxmm)
Dependency Confusion In ngx-extended-pdf-viewer
6.2
Medium
Ecosystem: Npm
Component: ngx-extended-pdf-viewer
FLAT-MED2C (CVE-2026-16633)
Reflected cross-site scripting (XSS) In pdfjs-dist
6.2
Medium
Ecosystem: Npm
Component: pdfjs-dist
FLAT-59VVB (CVE-2026-71497)
Reflected cross-site scripting (XSS) In org.jsoup:jsoup
0.6
Low
Ecosystem: Maven
Component: org.jsoup:jsoup
FLAT-F65MI (GHSA-p8x7-9vfw-p7vc)
Improper authorization control for web services In craftcms/cms
6.2
Medium
Ecosystem: Packagist
Component: craftcms/cms
FLAT-RAHKM (GHSA-f5wm-88jv-g5hx)
Security controls bypass or absence In craftcms/cms
6.3
Medium
Ecosystem: Packagist
Component: craftcms/cms
FLAT-Z420T (CVE-2026-14793)
Improper authorization control for web services In craftcms/cms
0.6
Low
Ecosystem: Packagist
Component: craftcms/cms
FLAT-M75WL (GHSA-265m-7826-wjqm)
Insecure deserialization In craftcms/cms
6.3
Medium
Ecosystem: Packagist
Component: craftcms/cms
FLAT-C2K6G (GHSA-mj63-m3rc-8ppr)
Asymmetric denial of service In league/commonmark
1.7
Low
Ecosystem: Packagist
Component: league/commonmark
FLAT-8DEYZ (GHSA-mh25-x5hq-wrqp)
Improper resource allocation In league/commonmark
4.6
Medium
Ecosystem: Packagist
Component: league/commonmark
FLAT-CMMUK (GHSA-jfm3-95jq-q3rf)
Improper resource allocation In league/commonmark
4.6
Medium
Ecosystem: Packagist
Component: league/commonmark
FLAT-7LNPD (GHSA-g2gp-3wwq-f4ph)
Improper resource allocation In league/commonmark
4.6
Medium
Ecosystem: Packagist
Component: league/commonmark
FLAT-9H67Q (CVE-2026-71488)
Improper resource allocation In league/commonmark
6.6
Medium
Ecosystem: Packagist
Component: league/commonmark
FLAT-ER18N (CVE-2026-71478)
Server side cross-site scripting In league/commonmark
0.5
Low
Ecosystem: Packagist
Component: league/commonmark
FLAT-6QUQK (GHSA-5p4m-2wfm-xmqj)
Improper resource allocation In js-yaml
6.6
Medium
Ecosystem: Npm
Component: js-yaml
FLAT-OOFU2 (CVE-2026-54717)
Server side cross-site scripting In silverstripe/cms
5.0
Medium
Ecosystem: Packagist
Component: silverstripe/cms
FLAT-B6KZ1 (CVE-2026-18654)
Security controls bypass or absence In awscli
2.4
Low
Ecosystem: PyPI
Component: awscli
FLAT-1THQ0 (CVE-2026-71476)
Lack of data validation - Path Traversal In @nx/powerpack-azure-cache
6.3
Medium
Ecosystem: Npm
Component: @nx/powerpack-azure-cache
FLAT-N2QAF (CVE-2026-71439)
Improper authorization control for web services In mermaid
1.3
Low
Ecosystem: Npm
Component: mermaid
FLAT-XCX7Y (CVE-2026-71438)
Prototype Pollution In mermaid
0.5
Low
Ecosystem: Npm
Component: mermaid
FLAT-JLMQ8 (CVE-2026-50159)
Server side template injection In mermaid
1.3
Low
Ecosystem: Npm
Component: mermaid
FLAT-FZMSY (CVE-2026-71437)
Prototype Pollution In mermaid
2.6
Low
Ecosystem: Npm
Component: mermaid
FLAT-XAV6V (CVE-2026-55825)
Lack of data validation - Path Traversal In contao/core-bundle
0.6
Low
Ecosystem: Packagist
Component: contao/core-bundle
FLAT-NI5NP (CVE-2026-71436)
Improper resource allocation In mermaid
1.3
Low
Ecosystem: Npm
Component: mermaid
FLAT-580H4 (CVE-2026-55824)
Business information leak In contao/core-bundle
2.3
Low
Ecosystem: Packagist
Component: contao/core-bundle
FLAT-QNXVY (CVE-2026-71435)
Server side cross-site scripting In statamic/cms
1.3
Low
Ecosystem: Packagist
Component: statamic/cms
FLAT-TK1MM (CVE-2026-71434)
Insecure file upload In statamic/cms
1.7
Low
Ecosystem: Packagist
Component: statamic/cms
FLAT-E5GP2 (CVE-2026-64662)
Improper authorization control for web services In statamic/cms
2.3
Low
Ecosystem: Packagist
Component: statamic/cms
FLAT-2P55J (CVE-2026-64663)
Remote command execution In statamic/cms
4.9
Medium
Ecosystem: Packagist
Component: statamic/cms
FLAT-UWXJU (CVE-2026-64665)
Authentication mechanism absence or evasion In statamic/cms
6.9
Medium
Ecosystem: Packagist
Component: statamic/cms
FLAT-29AMA (CVE-2026-64664)
Improper authorization control for web services In statamic/cms
0.6
Low
Ecosystem: Packagist
Component: statamic/cms
FLAT-T7T4C (CVE-2026-71433)
Unauthorized access to screen In langgraph-checkpoint-postgres
2.3
Low
Ecosystem: PyPI
Component: langgraph-checkpoint-postgres
FLAT-5G1LC (CVE-2026-54763)
Spoofing In github.com/traefik/traefik/v2
4.7
Medium
Ecosystem: Go
Component: github.com/traefik/traefik/v2
FLAT-AYOKZ (CVE-2026-65600)
Lack of data validation - Path Traversal In github.com/traefik/traefik/v2
6.9
Medium
Ecosystem: Go
Component: github.com/traefik/traefik/v2
FLAT-FZZUM (CVE-2026-67309)
Lack of data validation - Path Traversal In github.com/traefik/traefik/v3
4.7
Medium
Ecosystem: Go
Component: github.com/traefik/traefik/v3
FLAT-M1GOC (CVE-2026-54765)
Improper authorization control for web services In github.com/traefik/traefik/v3
2.3
Low
Ecosystem: Go
Component: github.com/traefik/traefik/v3
FLAT-2ZEHI (CVE-2026-71325)
Lack of isolation methods In github.com/traefik/traefik
1.1
Low
Ecosystem: Go
Component: github.com/traefik/traefik
FLAT-O0FMO (CVE-2026-54764)
Insufficient data authenticity validation In github.com/traefik/traefik
2.7
Low
Ecosystem: Go
Component: github.com/traefik/traefik
FLAT-GB0WF (CVE-2026-71327)
Sensitive information in source code In github.com/traefik/traefik/v3
6.0
Medium
Ecosystem: Go
Component: github.com/traefik/traefik/v3
FLAT-SS2D5 (CVE-2026-71326)
Improper authorization control for web services In github.com/traefik/traefik/v3
0.5
Low
Ecosystem: Go
Component: github.com/traefik/traefik/v3
FLAT-S646T (CVE-2026-71324)
HTTP request smuggling In github.com/traefik/traefik/v3
2.7
Low
Ecosystem: Go
Component: github.com/traefik/traefik/v3
FLAT-X4Z17 (CVE-2026-68750)
Improper resource allocation In html_sanitize_ex
4.6
Medium
Ecosystem: Hex
Component: html_sanitize_ex
FLAT-YBRZZ (CVE-2026-68749)
Asymmetric denial of service - ReDoS In html_sanitize_ex
4.6
Medium
Ecosystem: Hex
Component: html_sanitize_ex
FLAT-0M26X (CVE-2026-68747)
Remote command execution In html_sanitize_ex
0.6
Low
Ecosystem: Hex
Component: html_sanitize_ex
FLAT-HCODG (CVE-2026-66829)
Uncontrolled external site redirect In html_sanitize_ex
0.6
Low
Ecosystem: Hex
Component: html_sanitize_ex
FLAT-2GCE3 (CVE-2026-66370)
Uncontrolled external site redirect In html_sanitize_ex
1.1
Low
Ecosystem: Hex
Component: html_sanitize_ex
FLAT-PY9I4 (CVE-2026-66843)
Insecure service configuration In html_sanitize_ex
0.6
Low
Ecosystem: Hex
Component: html_sanitize_ex
FLAT-PVVTV (MAL-2026-13428)
Use of software with malware In @love-moon/conductor-cli
5.2
Medium
Ecosystem: Npm
Component: @love-moon/conductor-cli
FLAT-M1W1W (MAL-2026-13427)
Use of software with malware In @leejungkiin/awkit
5.2
Medium
Ecosystem: Npm
Component: @leejungkiin/awkit
FLAT-O0W6G (MAL-2026-13419)
Use of software with malware In @holocronlab/botruntime-runtime
5.2
Medium
Ecosystem: Npm
Component: @holocronlab/botruntime-runtime
FLAT-SJYPI (MAL-2026-13420)
Use of software with malware In @innocarpe/deepseek-build
5.2
Medium
Ecosystem: Npm
Component: @innocarpe/deepseek-build
FLAT-UM3DD (MAL-2026-13423)
Use of software with malware In fetchrtds
5.2
Medium
Ecosystem: Npm
Component: fetchrtds
FLAT-BWYBT (MAL-2026-13424)
Use of software with malware In tailwindcss-hide-scrollbar
5.2
Medium
Ecosystem: Npm
Component: tailwindcss-hide-scrollbar
FLAT-3OF34 (MAL-2026-13416)
Use of software with malware In @bananacool467/ui-tools
5.2
Medium
Ecosystem: Npm
Component: @bananacool467/ui-tools
FLAT-BU8RT (MAL-2026-13418)
Use of software with malware In @ccfly/setup-linux-x64
5.2
Medium
Ecosystem: Npm
Component: @ccfly/setup-linux-x64
FLAT-U6ZZN (MAL-2026-13417)
Use of software with malware In @ccfly/setup-linux-arm64
5.2
Medium
Ecosystem: Npm
Component: @ccfly/setup-linux-arm64
FLAT-S4JMD (MAL-2026-13414)
Use of software with malware In @atom8n/inspector
5.2
Medium
Ecosystem: Npm
Component: @atom8n/inspector
FLAT-ICXX1 (MAL-2026-13413)
Use of software with malware In @astralcore/aura-wb
5.2
Medium
Ecosystem: Npm
Component: @astralcore/aura-wb
FLAT-P5NCY (MAL-2026-13415)
Use of software with malware In @aubea/mars
5.2
Medium
Ecosystem: Npm
Component: @aubea/mars
FLAT-G5HDZ (MAL-2026-13426)
Use of software with malware In xayoub-xctxteam
5.2
Medium
Ecosystem: PyPI
Component: xayoub-xctxteam
FLAT-X3T55 (MAL-2026-13410)
Use of software with malware In @addai/entity-runtime
5.2
Medium
Ecosystem: Npm
Component: @addai/entity-runtime
FLAT-ZPWFH (MAL-2026-13411)
Use of software with malware In @addai/node
5.2
Medium
Ecosystem: Npm
Component: @addai/node
FLAT-AWKKX (MAL-2026-13409)
Use of software with malware In @addai/ainode
5.2
Medium
Ecosystem: Npm
Component: @addai/ainode
FLAT-CWGP4 (MAL-2026-13408)
Use of software with malware In @activepieces/piece-base44
5.2
Medium
Ecosystem: Npm
Component: @activepieces/piece-base44
FLAT-TYNX3 (MAL-2026-13407)
Use of software with malware In @0l00000l/auth
5.2
Medium
Ecosystem: Npm
Component: @0l00000l/auth
FLAT-1873T (MAL-2026-13406)
Use of software with malware In 9remote
5.2
Medium
Ecosystem: Npm
Component: 9remote
FLAT-D39ZG (MAL-2026-13422)
Use of software with malware In beautiful-ui-monitoring
5.2
Medium
Ecosystem: Npm
Component: beautiful-ui-monitoring
FLAT-UYJW8 (MAL-2026-13421)
Use of software with malware In @trackunit/iris-app-sdk-vite
5.2
Medium
Ecosystem: Npm
Component: @trackunit/iris-app-sdk-vite
FLAT-XN786 (MAL-2026-13412)
Use of software with malware In @apicity/meta
5.2
Medium
Ecosystem: Npm
Component: @apicity/meta
FLAT-76FIG (MAL-2026-13425)
Use of software with malware In typst-resume-cli
5.2
Medium
Ecosystem: Npm
Component: typst-resume-cli
FLAT-PL2GZ (MAL-2026-13400)
Use of software with malware In agenttunnels
5.2
Medium
Ecosystem: Npm
Component: agenttunnels
FLAT-XDEVB (MAL-2026-13394)
Use of software with malware In @activepieces/piece-google-bigquery
5.2
Medium
Ecosystem: Npm
Component: @activepieces/piece-google-bigquery
FLAT-6YBWM (MAL-2026-13395)
Use of software with malware In @activepieces/piece-google-contacts
5.2
Medium
Ecosystem: Npm
Component: @activepieces/piece-google-contacts
FLAT-Z85ZN (MAL-2026-13396)
Use of software with malware In @activepieces/piece-google-forms
5.2
Medium
Ecosystem: Npm
Component: @activepieces/piece-google-forms
FLAT-6NYV0 (MAL-2026-13404)
Use of software with malware In tsihealth-client
5.2
Medium
Ecosystem: Npm
Component: tsihealth-client
FLAT-JHV1S (MAL-2026-13398)
Use of software with malware In @xiaohhhh1/canvas-agent
5.2
Medium
Ecosystem: Npm
Component: @xiaohhhh1/canvas-agent
FLAT-QZ5O3 (MAL-2026-13397)
Use of software with malware In @vanexalabs-ai/vanexa-agent
5.2
Medium
Ecosystem: Npm
Component: @vanexalabs-ai/vanexa-agent
FLAT-6CYN1 (MAL-2026-13405)
Use of software with malware In vitest-preview-pro-all
5.2
Medium
Ecosystem: Npm
Component: vitest-preview-pro-all
FLAT-RU74M (MAL-2026-13399)
Use of software with malware In agenthub-multiagent-mcp
5.2
Medium
Ecosystem: Npm
Component: agenthub-multiagent-mcp
FLAT-PMUY8 (MAL-2026-13403)
Use of software with malware In streak-cache-map
5.2
Medium
Ecosystem: Npm
Component: streak-cache-map
FLAT-DY35Z (MAL-2026-13401)
Use of software with malware In helmet-pro
5.2
Medium
Ecosystem: Npm
Component: helmet-pro
FLAT-UA292 (MAL-2026-13402)
Use of software with malware In jagproject
5.2
Medium
Ecosystem: Npm
Component: jagproject
FLAT-VVAUN (MAL-2026-13393)
Use of software with malware In wallet-monitor-snap
5.2
Medium
Ecosystem: Npm
Component: wallet-monitor-snap
FLAT-XTQG0 (MAL-2026-13392)
Use of software with malware In golaaa
5.2
Medium
Ecosystem: Npm
Component: golaaa
FLAT-6NINN (GHSA-6976-qm5m-7mcj)
Out-of-bounds read In viperjs
6.7
Medium
Ecosystem: Cargo
Component: viperjs
FLAT-GJ3HQ (MAL-2026-13386)
Use of software with malware In decapod-common
5.2
Medium
Ecosystem: PyPI
Component: decapod-common
FLAT-1DA6H (MAL-2026-13391)
Use of software with malware In @zahlen/checkout
5.2
Medium
Ecosystem: Npm
Component: @zahlen/checkout
FLAT-MV8Q5 (MAL-2026-13389)
Use of software with malware In @voxepay/checkout
5.2
Medium
Ecosystem: Npm
Component: @voxepay/checkout
FLAT-JTB3W (MAL-2026-13387)
Use of software with malware In @afasinatickets/common
5.2
Medium
Ecosystem: Npm
Component: @afasinatickets/common
FLAT-LA94L (MAL-2026-13388)
Use of software with malware In @simplipayng/checkout
5.2
Medium
Ecosystem: Npm
Component: @simplipayng/checkout
FLAT-BN2PQ (MAL-2026-13390)
Use of software with malware In @xsat10/baileys-xsat
5.2
Medium
Ecosystem: Npm
Component: @xsat10/baileys-xsat