FLAT-S6RZ7 (CVE-2026-82405)
Improper authorization control for web services In github.com/klever-io/klever-go
6.3
Medium
Ecosystem: Go
Component: github.com/klever-io/klever-go
FLAT-0S7U6 (CVE-2026-86065)
Improper resource allocation In github.com/klever-io/klever-go
6.6
Medium
Ecosystem: Go
Component: github.com/klever-io/klever-go
FLAT-4ANH1 (CVE-2026-86064)
Unauthorized access to screen In github.com/klever-io/klever-go
6.8
Medium
Ecosystem: Go
Component: github.com/klever-io/klever-go
FLAT-8UGA0 (CVE-2026-93421)
Log injection In mesop
1.3
Low
Ecosystem: PyPI
Component: mesop
FLAT-MM4NV (CVE-2026-77602)
Remote command execution In openc3
6.1
Medium
Ecosystem: RubyGems
Component: openc3
FLAT-YYZK2 (CVE-2026-77601)
Remote command execution In openc3
5.2
Medium
Ecosystem: RubyGems
Component: openc3
FLAT-9ZUD0 (CVE-2026-61695)
Lack of data validation In github.com/square/wire
6.6
Medium
Ecosystem: SwiftURL
Component: github.com/square/wire
FLAT-24O03 (CVE-2026-76087)
Improper authorization control for web services In verbb/formie
6.7
Medium
Ecosystem: Packagist
Component: verbb/formie
FLAT-LJZX0 (CVE-2026-76086)
Server-side request forgery (SSRF) In verbb/formie
6.0
Medium
Ecosystem: Packagist
Component: verbb/formie
FLAT-JCG2J (MAL-2026-16482)
Use of software with malware In internallib_v657
5.2
Medium
Ecosystem: Npm
Component: internallib_v657
FLAT-78EIW (MAL-2026-16481)
Use of software with malware In internallib_v463
5.2
Medium
Ecosystem: Npm
Component: internallib_v463
FLAT-E9JW3 (MAL-2026-16480)
Use of software with malware In a-onesite
5.2
Medium
Ecosystem: Npm
Component: a-onesite
FLAT-ZNS1V (CVE-2026-92692)
SQL injection In sulu/sulu
2.7
Low
Ecosystem: Packagist
Component: sulu/sulu
FLAT-M0NCM (CVE-2026-77421)
Asymmetric denial of service - ReDoS In org.jline:jline-builtins
4.6
Medium
Ecosystem: Maven
Component: org.jline:jline-builtins
FLAT-AHCLH (CVE-2026-77422)
Asymmetric denial of service - ReDoS In org.jline:jline-builtins
4.6
Medium
Ecosystem: Maven
Component: org.jline:jline-builtins
FLAT-OL8AH (CVE-2026-56679)
Insecure deserialization In 9router
6.2
Medium
Ecosystem: Npm
Component: 9router
FLAT-YS1QP (CVE-2026-56678)
Server-side request forgery (SSRF) In 9router
5.9
Medium
Ecosystem: Npm
Component: 9router
FLAT-0SO2H (CVE-2026-56676)
Server-side request forgery (SSRF) In 9router
6.7
Medium
Ecosystem: Npm
Component: 9router
FLAT-ZYA0Q (CVE-2026-56675)
Authentication mechanism absence or evasion In 9router
1.7
Low
Ecosystem: Npm
Component: 9router
FLAT-8IU51 (CVE-2026-77420)
Asymmetric denial of service - ReDoS In org.jline:jline-reader
0.6
Low
Ecosystem: Maven
Component: org.jline:jline-reader
FLAT-JAG8D (CVE-2026-96382)
Server side cross-site scripting In drupal/diba_carousel
2.7
Low
Ecosystem: Packagist
Component: drupal/diba_carousel
FLAT-3QPDQ (CVE-2026-96386)
Improper authorization control for web services In drupal/smart_content
1.7
Low
Ecosystem: Packagist
Component: drupal/smart_content
FLAT-HRQDA (CVE-2026-96380)
Cross-site request forgery In drupal/css_usage_analyzer
0.6
Low
Ecosystem: Packagist
Component: drupal/css_usage_analyzer
FLAT-IF1QL (CVE-2026-96377)
Improper authorization control for web services In drupal/combined_image_style
6.6
Medium
Ecosystem: Packagist
Component: drupal/combined_image_style
FLAT-XH73S (CVE-2026-96392)
Server side template injection In drupal/ai_ckeditor
9.0
Critical
Ecosystem: Packagist
Component: drupal/ai_ckeditor
FLAT-O7593 (CVE-2026-96391)
Improper authorization control for web services In drupal/webform_rest
2.7
Low
Ecosystem: Packagist
Component: drupal/webform_rest
FLAT-VAUES (CVE-2026-96390)
Improper authorization control for web services In drupal/editoria11y
2.7
Low
Ecosystem: Packagist
Component: drupal/editoria11y
FLAT-X6F35 (CVE-2026-96388)
Cross-site request forgery In drupal/tawk_to
0.6
Low
Ecosystem: Packagist
Component: drupal/tawk_to
FLAT-8HV7Y (CVE-2026-96387)
Authentication mechanism absence or evasion In drupal/stop_admin
2.1
Low
Ecosystem: Packagist
Component: drupal/stop_admin
FLAT-ZPRP4 (CVE-2026-96385)
Authentication mechanism absence or evasion In drupal/rest_api_authentication
2.7
Low
Ecosystem: Packagist
Component: drupal/rest_api_authentication
FLAT-8OH7S (CVE-2026-96379)
Server side cross-site scripting In drupal/cookiecuttr
2.1
Low
Ecosystem: Packagist
Component: drupal/cookiecuttr
FLAT-V1X2O (CVE-2026-96384)
Enabled default configuration In drupal/mermaid_diagram_field
1.7
Low
Ecosystem: Packagist
Component: drupal/mermaid_diagram_field
FLAT-XKBIT (CVE-2026-96378)
Server side cross-site scripting In drupal/commerce_decoupled_checkout
8.9
High
Ecosystem: Packagist
Component: drupal/commerce_decoupled_checkout
FLAT-LVSUP (CVE-2026-96374)
Cross-site request forgery In drupal/project_browser
0.6
Low
Ecosystem: Packagist
Component: drupal/project_browser
FLAT-ESUWL (CVE-2026-96376)
Server side template injection In drupal/cloud
6.0
Medium
Ecosystem: Packagist
Component: drupal/cloud
FLAT-2EPMP (CVE-2026-96375)
Insufficient data authenticity validation In drupal/cloud
2.3
Low
Ecosystem: Packagist
Component: drupal/cloud
FLAT-ILLPX (CVE-2026-96355)
Lack of data validation - Modify DOM Elements In drupal/webform
0.6
Low
Ecosystem: Packagist
Component: drupal/webform
FLAT-I2EN5 (CVE-2026-96356)
Improper authorization control for web services In drupal/webform
1.7
Low
Ecosystem: Packagist
Component: drupal/webform
FLAT-84NRU (CVE-2026-96398)
Improper authorization control for web services In drupal/webform
0.6
Low
Ecosystem: Packagist
Component: drupal/webform
FLAT-ZQ4N7 (CVE-2026-96357)
Insecure file upload In drupal/webform
0.4
Low
Ecosystem: Packagist
Component: drupal/webform
FLAT-6QUXJ (CVE-2026-96364)
Cross-site request forgery In drupal/webform
0.6
Low
Ecosystem: Packagist
Component: drupal/webform
FLAT-KONZ0 (CVE-2026-96365)
Cross-site request forgery In drupal/webform
4.8
Medium
Ecosystem: Packagist
Component: drupal/webform
FLAT-PN5AR (CVE-2026-96366)
Insecure file upload In drupal/webform
0.6
Low
Ecosystem: Packagist
Component: drupal/webform
FLAT-SCXEJ (CVE-2026-96373)
Unauthorized access to files In drupal/webform
0.6
Low
Ecosystem: Packagist
Component: drupal/webform
FLAT-0Z6NW (CVE-2026-96372)
Improper authorization control for web services In drupal/webform
0.6
Low
Ecosystem: Packagist
Component: drupal/webform
FLAT-PKAVU (CVE-2026-96371)
Improper authorization control for web services In drupal/webform
0.6
Low
Ecosystem: Packagist
Component: drupal/webform
FLAT-3MZ8M (CVE-2026-96369)
Business information leak In drupal/webform
0.6
Low
Ecosystem: Packagist
Component: drupal/webform
FLAT-LJJBC (CVE-2026-96370)
Server-side request forgery (SSRF) In drupal/webform
6.1
Medium
Ecosystem: Packagist
Component: drupal/webform
FLAT-0A5WU (CVE-2026-96368)
Server side cross-site scripting In drupal/webform
5.9
Medium
Ecosystem: Packagist
Component: drupal/webform
FLAT-D9BDP (CVE-2026-96367)
Server side cross-site scripting In drupal/webform
5.9
Medium
Ecosystem: Packagist
Component: drupal/webform
FLAT-E471N (CVE-2026-96363)
Server side cross-site scripting In drupal/webform
4.2
Medium
Ecosystem: Packagist
Component: drupal/webform
FLAT-7APJG (CVE-2026-96362)
Reflected cross-site scripting (XSS) In drupal/webform
0.6
Low
Ecosystem: Packagist
Component: drupal/webform
FLAT-BKNEM (CVE-2026-96359)
Reflected cross-site scripting (XSS) In drupal/webform
0.6
Low
Ecosystem: Packagist
Component: drupal/webform
FLAT-VO174 (CVE-2026-96358)
Server side cross-site scripting In drupal/webform
6.5
Medium
Ecosystem: Packagist
Component: drupal/webform
FLAT-3GXOC (CVE-2026-96361)
Reflected cross-site scripting (XSS) In drupal/webform
0.5
Low
Ecosystem: Packagist
Component: drupal/webform
FLAT-FCWBI (CVE-2026-96360)
Reflected cross-site scripting (XSS) In drupal/webform
0.4
Low
Ecosystem: Packagist
Component: drupal/webform
FLAT-4MGHF (CVE-2026-85724)
Asymmetric denial of service - ReDoS In io.moquette:moquette-broker
8.4
High
Ecosystem: Maven
Component: io.moquette:moquette-broker
FLAT-8PKWQ (CVE-2026-73858)
Server side template injection In solspace/craft-freeform
1.7
Low
Ecosystem: Packagist
Component: solspace/craft-freeform
FLAT-SWVSR (MAL-2026-16478)
Use of software with malware In event-hunter
5.2
Medium
Ecosystem: Npm
Component: event-hunter
FLAT-1HQLX (CVE-2026-88974)
Improper authorization control for web services In wp-graphql/wp-graphql
0.6
Low
Ecosystem: Packagist
Component: wp-graphql/wp-graphql
FLAT-LFUNT (MAL-2026-16479)
Use of software with malware In simplenewnpmpackage
5.2
Medium
Ecosystem: Npm
Component: simplenewnpmpackage
FLAT-ZM4NN (MAL-2026-16477)
Use of software with malware In com.apple.unityplugin.storekit
5.2
Medium
Ecosystem: Npm
Component: com.apple.unityplugin.storekit
FLAT-G169H (CVE-2026-63000)
Cross-site request forgery In redaxo/source
2.0
Low
Ecosystem: Packagist
Component: redaxo/source
FLAT-9D1YY (CVE-2026-63002)
Server side cross-site scripting In redaxo/source
3.4
Low
Ecosystem: Packagist
Component: redaxo/source
FLAT-RV17D (CVE-2026-63001)
Server side cross-site scripting In redaxo/source
5.3
Medium
Ecosystem: Packagist
Component: redaxo/source
FLAT-G55EF (CVE-2026-61541)
Asymmetric denial of service In zapros
2.7
Low
Ecosystem: PyPI
Component: zapros
FLAT-K1HCN (CVE-2026-61652)
Inadequate file size control In zapros
6.6
Medium
Ecosystem: PyPI
Component: zapros
FLAT-UAAF7 (CVE-2026-57149)
Remote command execution In plone-app-portlets
7.7
High
Ecosystem: PyPI
Component: plone-app-portlets
FLAT-0PDHY (RUSTSEC-2026-0305)
Improper resource allocation In librsvg
1.7
Low
Ecosystem: Cargo
Component: librsvg
FLAT-GY5XG (MAL-2026-16476)
Use of software with malware In @memtensor/memos-cloud-openclaw-plugin
5.2
Medium
Ecosystem: Npm
Component: @memtensor/memos-cloud-openclaw-plugin
FLAT-OITJ1 (MAL-2026-16475)
Use of software with malware In memoryos
5.2
Medium
Ecosystem: PyPI
Component: memoryos
FLAT-8MLG8 (MAL-2026-16473)
Use of software with malware In sea-baileys
5.2
Medium
Ecosystem: Npm
Component: sea-baileys
FLAT-04X03 (MAL-2026-16474)
Use of software with malware In vite-dev-launcher
5.2
Medium
Ecosystem: Npm
Component: vite-dev-launcher
FLAT-IYUIA (MAL-2026-16467)
Use of software with malware In @test1230504/probe-7f3k2m-utils
5.2
Medium
Ecosystem: Npm
Component: @test1230504/probe-7f3k2m-utils
FLAT-M2YJQ (MAL-2026-16468)
Use of software with malware In @test1230504/string-format-helper
5.2
Medium
Ecosystem: Npm
Component: @test1230504/string-format-helper
FLAT-2HAQ0 (MAL-2026-16469)
Use of software with malware In @test1230504/test-publish-verify
5.2
Medium
Ecosystem: Npm
Component: @test1230504/test-publish-verify
FLAT-05AA0 (MAL-2026-16472)
Use of software with malware In z-deno-truth-ya1t4m
5.2
Medium
Ecosystem: Npm
Component: z-deno-truth-ya1t4m
FLAT-WX8TB (MAL-2026-16471)
Use of software with malware In z-deno-truth-va499w
5.2
Medium
Ecosystem: Npm
Component: z-deno-truth-va499w
FLAT-T8GA3 (MAL-2026-16470)
Use of software with malware In z-deno-truth-bwhlsz
5.2
Medium
Ecosystem: Npm
Component: z-deno-truth-bwhlsz
FLAT-Q35GY (MAL-2026-16464)
Use of software with malware In hachutis
5.2
Medium
Ecosystem: Npm
Component: hachutis
FLAT-RXUA7 (MAL-2026-16465)
Use of software with malware In helpersutils-dev-tools
5.2
Medium
Ecosystem: Npm
Component: helpersutils-dev-tools
FLAT-GUH1G (MAL-2026-16461)
Use of software with malware In godxxx
5.2
Medium
Ecosystem: Npm
Component: godxxx
FLAT-W0JA3 (MAL-2026-16462)
Use of software with malware In godzz
5.2
Medium
Ecosystem: Npm
Component: godzz
FLAT-2QB37 (MAL-2026-16463)
Use of software with malware In godzzz
5.2
Medium
Ecosystem: Npm
Component: godzzz
FLAT-65BT5 (MAL-2026-16446)
Use of software with malware In better-md
5.2
Medium
Ecosystem: Npm
Component: better-md
FLAT-KOHW4 (MAL-2026-16455)
Use of software with malware In some-tool-package
5.2
Medium
Ecosystem: Npm
Component: some-tool-package
FLAT-6CI5X (MAL-2026-16453)
Use of software with malware In semver-bump-io
5.2
Medium
Ecosystem: Npm
Component: semver-bump-io
FLAT-GTPTM (MAL-2026-16448)
Use of software with malware In debounce-throttle-base
5.2
Medium
Ecosystem: Npm
Component: debounce-throttle-base
FLAT-IZD1P (MAL-2026-16449)
Use of software with malware In iso-datetime-core
5.2
Medium
Ecosystem: Npm
Component: iso-datetime-core
FLAT-MEKWD (MAL-2026-16454)
Use of software with malware In solo-async-pipe
5.2
Medium
Ecosystem: Npm
Component: solo-async-pipe
FLAT-P2C2N (MAL-2026-16459)
Use of software with malware In webp-https-errors
5.2
Medium
Ecosystem: Npm
Component: webp-https-errors
FLAT-GX429 (MAL-2026-16442)
Use of software with malware In moudeva
5.2
Medium
Ecosystem: Npm
Component: moudeva
FLAT-961BM (MAL-2026-16441)
Use of software with malware In moidevl
5.2
Medium
Ecosystem: Npm
Component: moidevl
FLAT-4XU42 (MAL-2026-16450)
Use of software with malware In kamafhbnowct
5.2
Medium
Ecosystem: Npm
Component: kamafhbnowct
FLAT-5SNQM (MAL-2026-16456)
Use of software with malware In tib2jcvowuyma
5.2
Medium
Ecosystem: Npm
Component: tib2jcvowuyma
FLAT-9WGM5 (MAL-2026-16457)
Use of software with malware In tibcwmpoeafh
5.2
Medium
Ecosystem: Npm
Component: tibcwmpoeafh
FLAT-GALFC (MAL-2026-16451)
Use of software with malware In luftzxyuiwgbgsp
5.2
Medium
Ecosystem: Npm
Component: luftzxyuiwgbgsp
FLAT-KX5NF (MAL-2026-16458)
Use of software with malware In tuxcmdfhjkw
5.2
Medium
Ecosystem: Npm
Component: tuxcmdfhjkw
FLAT-OUVWI (MAL-2026-16460)
Use of software with malware In xsjukcnv8low26
5.2
Medium
Ecosystem: Npm
Component: xsjukcnv8low26
FLAT-TNKL5 (MAL-2026-16447)
Use of software with malware In caphsmgiwy
5.2
Medium
Ecosystem: Npm
Component: caphsmgiwy