Live Threat Feed
A continuously updated record of high severity software supply chain attacks and actively exploited vulnerabilities that 0Day surfaces automatically. Each entry climbs a three stage confidence pipeline: Candidate → Early Warning → Confirmed, and pages update automatically as new sources corroborate a threat.
EARLY WARNINGPACKAGISTSEPTEMBER 2026
Cotonti Comments Plugin Vulnerability: Critical Risk AlertEarly warning of a critical vulnerability in Cotonti Comments plugin version 1.0.0. Assess your exposure now.
EARLY WARNINGNPMSEPTEMBER 2026
@zereight/mcp-gitlab npm Package SSRF VulnerabilityEarly warning of a high-severity SSRF vulnerability in @zereight/mcp-gitlab npm package. Assess your exposure now.
EARLY WARNINGNPMSEPTEMBER 2026
zereight/gitlab-mcp npm Package SSRF Vulnerability: Early WarningEarly warning of a potential SSRF vulnerability in the zereight/gitlab-mcp npm package. Consult the sources for details.
EARLY WARNINGNPMSEPTEMBER 2026
Potential DNS Rebinding Attack on @zereight/mcp-gitlab npm PackageEarly warning: @zereight/mcp-gitlab npm package may be vulnerable to DNS rebinding attacks. Upgrade to version 2.1.30 or later.
EARLY WARNINGCARGOSEPTEMBER 2026
libp2p-quic Panic Vulnerability: Early Warning for Software EngineersEarly warning for a potential panic vulnerability in libp2p-quic. Learn about the issue and how to assess your exposure.
EARLY WARNINGMAVENSEPTEMBER 2026
http4s-ember-core Maven Package Vulnerability: Early WarningEarly warning of a vulnerability in http4s-ember-core Maven package that may lead to HTTP request smuggling.
EARLY WARNINGPHPSEPTEMBER 2026
Issabel Framework Vulnerability: Critical JWT Signing Key IssueEarly warning of a critical vulnerability in the Issabel Framework allowing remote command execution.
EARLY WARNINGCSEPTEMBER 2026
Ghostscript <= 10.07.0 Buffer Overflow Vulnerability: Early WarningEarly warning of a critical buffer overflow vulnerability in Ghostscript <= 10.07.0. Upgrade to 10.08.0 or later.
EARLY WARNINGNPMSEPTEMBER 2026
IBM Langflow OSS Vulnerability: Critical Supply-Chain ThreatEarly warning of a critical vulnerability in IBM Langflow OSS versions 1.0.0 through 1.10.0.
EARLY WARNINGNPMSEPTEMBER 2026
Crallab npm Package Vulnerability: Critical CVE-2026-90945 WarningEarly warning for Crallab npm package users: critical vulnerability CVE-2026-90945 may expose systems to unauthenticated administrative access.
EARLY WARNINGNPMSEPTEMBER 2026
Casdoor <= 4.4.0 Vulnerability: Critical CVE-2026-90942 ExposureEarly warning: Casdoor <= 4.4.0 reportedly exposes private key, allowing JWT token forgery.
EARLY WARNINGPYPISEPTEMBER 2026
ESPHome Device Builder: Dashboard Authentication Issue on UpgradeEarly warning about a potential authentication issue in ESPHome Device Builder after upgrade.
EARLY WARNINGNPMSEPTEMBER 2026
Vite Development Servers Targeted in Cloud Credential Theft CampaignMass-scanning campaign exploits Vite flaw to steal AWS and Azure credentials from exposed development servers.
EARLY WARNINGCSEPTEMBER 2026
Froxlor Vulnerability CVE-2026-90937: Critical Configuration Injection RiskEarly warning on Froxlor versions before 2.2.5. Critical vulnerability allows configuration injection.
EARLY WARNINGNPMSEPTEMBER 2026
LightLLM Remote Code Execution Vulnerability: Early WarningLightLLM through 1.2.0 contains a critical remote code execution vulnerability. Upgrade immediately.
CONFIRMEDCISA_KEVSEPTEMBER 2026
Cisco Secure Email Gateway SQL Injection Vulnerability ExploitedCisco Secure Email Gateway has a critical SQL injection vulnerability that is actively exploited.
EARLY WARNINGNPMSEPTEMBER 2026
Tencent Sogou Input Method Vulnerability Exploited: Early WarningEarly warning: Tencent Sogou Input Method for Windows vulnerability exploited in the wild to deploy GrayRabbit backdoor.
CONFIRMEDNPMSEPTEMBER 2026
Critical Vulnerabilities in artifactory, screenconnect, routeros: What You Need to KnowCISA has added five security flaws in artifactory, screenconnect, and routeros to its KEV catalog due to active exploitation.
EARLY WARNINGWORDPRESSSEPTEMBER 2026
The Events Calendar WordPress Plugin Vulnerable to Remote Code ExecutionThe Events Calendar WordPress plugin is reportedly vulnerable to Remote Code Execution in versions up to 6.17.3.
EARLY WARNINGWORDPRESSSEPTEMBER 2026
The Events Calendar WordPress Plugin Vulnerable to Remote Code ExecutionThe Events Calendar plugin for WordPress is reportedly vulnerable to Remote Code Execution in versions up to 6.17.4.
CONFIRMEDGITHUB-ACTIONSSEPTEMBER 2026
GitLab API Path Traversal Vulnerability CVE-2026-85706 ExploitedGitLab has patched a critical vulnerability allowing unauthenticated file reading. Upgrade now.
EARLY WARNINGPYPISEPTEMBER 2026
Prowler SAML Vulnerability: Cross-Tenant Account Takeover RiskProwler SAML authentication flaw may enable cross-tenant account takeover. Review your configuration.
EARLY WARNINGMAVENSEPTEMBER 2026
Central Dogma Maven Package: Hard-coded Secret RiskEarly warning about a hard-coded replication secret in Central Dogma Maven package.
EARLY WARNINGMAVENSEPTEMBER 2026
Central Dogma Maven Package: Hard-coded Secret VulnerabilityEarly warning of a high-severity vulnerability in Central Dogma Maven package due to a hard-coded secret.
EARLY WARNINGPYPISEPTEMBER 2026
MySQL MCP Server Vulnerability: Unauthenticated SQL Execution RiskEarly warning of a vulnerability in MySQL MCP Server that allows unauthenticated SQL execution due to missing origin/host validation.
EARLY WARNINGPHPSEPTEMBER 2026
SPIP <= 4.4.17 Remote Code Execution Vulnerability: Early WarningEarly warning of a critical remote code execution vulnerability in SPIP <= 4.4.17. Upgrade to 4.4.18 or later.
CONFIRMEDNPMSEPTEMBER 2026
GitLab Commits API Vulnerability: Critical File-Read FlawCritical severity vulnerability in GitLab's commits API allows unauthenticated file reading. Confirmed exploit in the wild.
EARLY WARNINGNPMSEPTEMBER 2026
Hugo Static Site Generator Vulnerability: Critical CVE-2026-89259Hugo has a critical vulnerability allowing Node tools to read and write files outside the project's working directory.
EARLY WARNINGWORDPRESSSEPTEMBER 2026
MIPL Grouped Checkout Fields for WooCommerce Vulnerability AlertEarly warning of a critical vulnerability in MIPL Grouped Checkout Fields for WooCommerce <=1.2.1.
CONFIRMEDNPMSEPTEMBER 2026
JFrog Artifactory Vulnerability CVE-2026-42016 Exploited in the WildJFrog Artifactory contains an incorrect authorization vulnerability leading to privilege escalation. Upgrade now.
EARLY WARNINGNPMSEPTEMBER 2026
ConnectWise ScreenConnect Vulnerability: Early Warning and MitigationEarly warning of a high-severity vulnerability in ConnectWise ScreenConnect. Learn about the risk and mitigation steps.
CONFIRMEDCISA_KEVSEPTEMBER 2026
GitLab Path Traversal Vulnerability CVE-2026-85706: Critical ThreatGitLab Community and Enterprise Editions contain a critical path traversal vulnerability allowing unauthenticated file reading.
EARLY WARNINGGOSEPTEMBER 2026
rclone archive/zip: Zip Slip Vulnerability Under InvestigationEarly warning of a Zip Slip vulnerability in rclone archive/zip package. Upgrade to the latest version.
EARLY WARNINGGOSEPTEMBER 2026
rclone Configuration Mismatch: Unauthorized Access RiskEarly warning: rclone package versions v1.70.0 through v1.75.0 have a configuration mismatch leading to unauthorized access.
EARLY WARNINGGOSEPTEMBER 2026
rclone Go Package Vulnerability: Memory Exhaustion RiskEarly warning of a high severity vulnerability in rclone Go package that could lead to memory exhaustion.
EARLY WARNINGNPMSEPTEMBER 2026
IBM Langflow OSS Vulnerability: Critical CVE-2026-79724 AlertEarly warning of a critical vulnerability in IBM Langflow OSS versions 1.0.0 through 1.11.5.
EARLY WARNINGNPMSEPTEMBER 2026
OmniRoute npm Package RCE Vulnerability: Early WarningEarly warning of a remote code execution vulnerability in OmniRoute npm package <= 3.8.50.
CONFIRMEDNPMSEPTEMBER 2026
Critical Vulnerability in IBM Langflow OSS: CVE-2026-85025IBM Langflow OSS versions 1.0.0 through 1.11.5 have a critical vulnerability allowing arbitrary code execution.
EARLY WARNINGNPMSEPTEMBER 2026
n8n npm Package Vulnerability: Approval-Gate Bypass RiskEarly warning on n8n npm package vulnerability allowing approval-gate bypass. Upgrade to patched versions to mitigate risk.
CONFIRMEDNPMSEPTEMBER 2026
JFrog Artifactory Under Attack: Critical Vulnerabilities ExploitedActive exploitation of three critical vulnerabilities in JFrog Artifactory, leading to admin control and backdoor deployment.
EARLY WARNINGNPMSEPTEMBER 2026
passport-saml-encrypted Vulnerability: Critical CVE-2026-89042 AlertEarly warning for passport-saml-encrypted npm package vulnerability. Critical CVE-2026-89042 may allow attackers to bypass authentication.
EARLY WARNINGNPMSEPTEMBER 2026
Critical CVE-2026-88899 Vulnerability in cve-2026-88899 npm PackageEarly warning of a critical vulnerability in cve-2026-88899 npm package. Upgrade to 0.31.0 or later.
EARLY WARNINGNPMSEPTEMBER 2026
n8n npm Package Vulnerability: Domain-Restriction BypassEarly warning on a high-severity vulnerability in the n8n npm package. Learn about the domain-restriction bypass and how to assess your exposure.
CONFIRMEDPYPISEPTEMBER 2026
Open WebUI SSRF Vulnerability via DNS Rebinding in PlaywrightOpen WebUI package is vulnerable to SSRF via DNS rebinding in the Playwright web loader.
EARLY WARNINGPYPISEPTEMBER 2026
open webui Package Vulnerability: Unauthorized Chat InjectionEarly warning of a vulnerability in the open webui package that allows unauthorized chat injection.
EARLY WARNINGPYPISEPTEMBER 2026
Open WebUI Package Vulnerability: Early Warning and AssessmentEarly warning of a high severity vulnerability in the Open WebUI package. Assess your exposure and take recommended actions.
EARLY WARNINGPYPISEPTEMBER 2026
Open WebUI Vulnerability: Authenticated Users Can Access Azure ServicesEarly warning of a vulnerability in Open WebUI that allows authenticated users to reach Azure services.
CONFIRMEDGITHUB-ACTIONSSEPTEMBER 2026
Traefik 3.7.0, 3.7.11 Vulnerability: Critical CVE-2026-88877Traefik versions 3.7.0 to 3.7.11 have a critical vulnerability. Upgrade to 3.7.12 or later.
EARLY WARNINGNPMSEPTEMBER 2026
Capgo npm Package Vulnerability: Critical SSO Bypass RiskEarly warning of a critical vulnerability in the Capgo npm package that allows SSO bypass.
EARLY WARNINGNPMSEPTEMBER 2026
Critical SQL Injection Vulnerability in GisLab Laboratory Management SystemEarly warning of a critical SQL injection vulnerability in GisLab Laboratory Management System versions before 1.5.
EARLY WARNINGWORDPRESSSEPTEMBER 2026
Drag and Drop File Upload for Elementor Forms Plugin Vulnerability AlertCritical vulnerability in Drag and Drop File Upload for Elementor Forms plugin for WordPress. Upgrade now.
EARLY WARNINGNPMSEPTEMBER 2026
MikroTik RouterOS Vulnerability CVE-2026-86060: Early WarningEarly warning of a MikroTik RouterOS vulnerability that may allow privilege escalation.
EARLY WARNINGCISA_KEVSEPTEMBER 2026
MikroTik RouterOS Vulnerability: CVE-2026-67277 Early WarningEarly warning of a high-severity vulnerability in MikroTik RouterOS. CVE-2026-67277 is reportedly exploited in the wild.
EARLY WARNINGPYPISEPTEMBER 2026
Open WebUI Vulnerability: Server Hang via Cyclic Chat Tree DeletionEarly warning of a vulnerability in Open WebUI that allows server hang via cyclic chat tree deletion.
EARLY WARNINGGEMSEPTEMBER 2026
decidim-elections Gem Vulnerability: Stored XSS RiskEarly warning of a high-severity vulnerability in decidim-elections gem. Review administrator accesses and monitor for patches.
EARLY WARNINGPHPSEPTEMBER 2026
MaxSite CMS <=109.6 Vulnerability: Critical Session Key IssueMaxSite CMS <=109.6 has a critical hardcoded session encryption key vulnerability. Upgrade now.
EARLY WARNINGCARGOSEPTEMBER 2026
gix-sec Rust Crate Vulnerability: Potential Security Risk for Elevated AdminsEarly warning of a high severity vulnerability in gix-sec Rust crate affecting versions < 0.13.3.
EARLY WARNINGNUGETSEPTEMBER 2026
Microsoft.DiaSymReader.Native Vulnerability: Critical CVE AlertEarly warning of a critical remote code execution vulnerability in Microsoft.DiaSymReader.Native affecting.NET projects.
EARLY WARNINGNUGETSEPTEMBER 2026
Microsoft.DiaSymReader.Native Vulnerability: Critical CVE AlertEarly warning of a critical remote code execution vulnerability in Microsoft.DiaSymReader.Native affecting.NET projects.
EARLY WARNINGNPMSEPTEMBER 2026
V8 npm Package Vulnerability: Active Exploitation ReportedV8 npm package vulnerability, identified as CVE-2026-87491, is reportedly being exploited in the wild. Learn about the risk and mitigation steps.
CONFIRMEDCISA_KEVSEPTEMBER 2026
CVE-2026-20079: Cisco Secure FMC and SCC Firewall Management VulnerabilityCVE-2026-20079: Cisco Secure FMC and SCC Firewall Management contain an authentication bypass vulnerability exploited in the wild.
EARLY WARNINGCISA_KEVSEPTEMBER 2026
Fortinet Products Under Attack: CVE-2025-25249 ExploitedEarly warning of a high-severity vulnerability in Fortinet FortiOS, FortiSwitchManager, and FortiSASE.
EARLY WARNINGNPMSEPTEMBER 2026
Google Chromium V8 Vulnerability: Critical Out-of-Bounds WriteEarly warning of a high-severity vulnerability in Google Chromium V8, potentially allowing remote code execution.
EARLY WARNINGCISA_KEVSEPTEMBER 2026
Citrix NetScaler ADC and Gateway Authentication Bypass VulnerabilityEarly warning of a critical authentication bypass vulnerability in Citrix NetScaler ADC and Gateway.
EARLY WARNINGNPMSEPTEMBER 2026
Nodemailer Address Parser Vulnerability: Early WarningEarly warning of a high severity vulnerability in Nodemailer's address parser. No exploitation in the wild reported.
EARLY WARNINGNPMSEPTEMBER 2026
Astro and Sharp Vulnerability: Remote Code Execution RiskEarly warning of a high severity vulnerability in Astro and Sharp that could lead to remote code execution.
EARLY WARNINGNPMSEPTEMBER 2026
js-yaml npm Package Vulnerability: What We KnowEarly warning of a vulnerability in js-yaml npm package that could lead to prolonged CPU consumption.
EARLY WARNINGGOSEPTEMBER 2026
gRPC-Go xDS Servers: DoS Vulnerability via Missing HeadersEarly warning of a high-severity DoS vulnerability in gRPC-Go xDS servers due to missing :authority and Host headers.
EARLY WARNINGGOSEPTEMBER 2026
gRPC-Go xDS Servers: DoS Vulnerability via Missing HeadersEarly warning: gRPC-Go xDS servers may crash due to missing :authority and Host headers.
EARLY WARNINGNPMSEPTEMBER 2026
Next.js Image Optimization Vulnerability: AVIF File RiskEarly warning of a potential remote code execution vulnerability in Next.js image optimization when using AVIF files.
EARLY WARNINGNPMSEPTEMBER 2026
@xmldom/xmldom Injection VulnerabilityEarly warning of a high-severity injection vulnerability in @xmldom/xmldom.
EARLY WARNINGNPMSEPTEMBER 2026
xmldom npm Package Vulnerability: Early WarningEarly warning of a vulnerability in the xmldom npm package. Assess your exposure now.
EARLY WARNINGPACKAGISTSEPTEMBER 2026
Predis Redis Library Flaw: CRLF Smuggling RiskEarly warning of a critical CRLF neutralization flaw in Predis Redis library versions 3.0.0-RC1 to 3.3.0.
CONFIRMEDPACKAGISTSEPTEMBER 2026
CakePHP SQL Injection Vulnerability: CVE-2026-77635 DetailsCritical SQL injection vulnerability in CakePHP FunctionsBuilder::jsonValue() with Postgres driver. Upgrade now.
EARLY WARNINGNPMSEPTEMBER 2026
Next.js Vulnerability on Windows Servers: Early WarningEarly warning of a critical vulnerability in Next.js applications on Windows servers.
EARLY WARNINGNPMSEPTEMBER 2026
maplibre-gl npm Package XSS Vulnerability: What We KnowEarly warning of a cross-site scripting vulnerability in maplibre-gl npm package versions <= 6.4.0.
EARLY WARNINGPYPISEPTEMBER 2026
vLLM Package Vulnerability: SSRF and Arbitrary Local File ReadEarly warning of a high severity vulnerability in vLLM package. Check your version.
EARLY WARNINGPYPISEPTEMBER 2026
vLLM Package Vulnerability: SSRF and Arbitrary Local File ReadvLLM package has an SSRF vulnerability and arbitrary local file read in its MiMoV2OmniMultiModalProcessor.
EARLY WARNINGNUGETSEPTEMBER 2026
Microsoft QUIC Vulnerability: Critical CVE-2026-62815 AlertEarly warning: Microsoft QUIC use after free vulnerability. Assess your exposure now.
EARLY WARNINGNUGETSEPTEMBER 2026
Microsoft QUIC Use-After-Free Vulnerability: Early WarningEarly warning of a use-after-free vulnerability in Microsoft QUIC that could allow remote code execution.
EARLY WARNINGPYPISEPTEMBER 2026
gitpython Package Vulnerability: Arbitrary File Read RiskEarly warning of a high-severity vulnerability in gitpython allowing arbitrary file read.
EARLY WARNINGNPMSEPTEMBER 2026
Adobe Commerce Stored XSS Vulnerability: Early WarningEarly warning of a critical stored Cross-Site Scripting vulnerability in Adobe Commerce.
EARLY WARNINGPYPISEPTEMBER 2026
GitPython Package Vulnerability: Dormant Config Values Enable RCEGitPython package reportedly vulnerable to RCE due to a bug in handling multi-line git-config values.
EARLY WARNINGPYPISEPTEMBER 2026
GitPython Vulnerability: Dormant Config Values Enable RCEGitPython package affected by a vulnerability that allows for remote code execution via corrupted config values.
CONFIRMEDNUGETSEPTEMBER 2026
Visual Studio Buffer Overflow Vulnerability CVE-2026-71328 ConfirmedHigh severity vulnerability in Visual Studio allows remote code execution. Confirmed by multiple sources.
CONFIRMEDNUGETSEPTEMBER 2026
Visual Studio Buffer Overflow Vulnerability: Critical Security AlertHigh severity vulnerability in Visual Studio allows remote code execution. Monitor for updates.
EARLY WARNINGNUGETSEPTEMBER 2026
ASP.NET Core Vulnerability ReportedReported vulnerability in ASP.NET Core may allow denial of service attacks. Monitor for updates.
CONFIRMEDNPMSEPTEMBER 2026
Visual Studio Code Vulnerability CVE-2026-81376: Critical Security BypassCritical vulnerability in Visual Studio Code allows unauthorized network security bypass. Update to latest version.
EARLY WARNINGMAVENSEPTEMBER 2026
Spring Cloud Azure Authentication Vulnerability: Early WarningEarly warning of a critical improper authentication vulnerability in Spring Cloud Azure.
EARLY WARNINGNPMSEPTEMBER 2026
SWC HTML Minifier Vulnerability: Script Element Breakout RiskEarly warning of a potential vulnerability in SWC HTML minifier that may allow script element breakout.
EARLY WARNINGGOSEPTEMBER 2026
Semaphore OS Command Injection Vulnerability: Critical Early WarningEarly warning of a critical OS command injection vulnerability in Semaphore. Assess your exposure now.
EARLY WARNINGGOSEPTEMBER 2026
SiYuan Package Exposes Database View Structure to Anonymous ReadersEarly warning: SiYuan package exposes database view structure to anonymous readers via /api/av/getAttributeViewFieldViews.
EARLY WARNINGGOSEPTEMBER 2026
SiYuan Package Information Disclosure: Early WarningEarly warning of a potential information disclosure issue in SiYuan package affecting version v3.7.4-alpha.1.
EARLY WARNINGNPMSEPTEMBER 2026
DeepSeek Harness Vulnerability: Critical Authentication Bypass AlertEarly warning of a critical vulnerability in DeepSeek Harness that could allow full agent control.
EARLY WARNINGPYPISEPTEMBER 2026
NLTK Corpus Reader Sandbox Bypass Vulnerability: Early WarningEarly warning of a high severity vulnerability in NLTK's corpus readers that may allow sandbox bypass.
EARLY WARNINGPYPISEPTEMBER 2026
NLTK Package Vulnerability: Symlink-Based Arbitrary File ReadEarly warning of a vulnerability in NLTK package allowing symlink-based arbitrary file read.
EARLY WARNINGPYPISEPTEMBER 2026
NLTK Package Vulnerability: Path Traversal and Trusted-Root BypassEarly warning about a vulnerability in the NLTK package that allows path traversal and trusted-root bypass.
EARLY WARNINGNPMSEPTEMBER 2026
Critical Flaw Found in hawtio-operator: What Software Engineers Need to KnowEarly warning of a critical flaw in hawtio-operator. Learn what is known and how to assess your exposure.
CONFIRMEDNPMSEPTEMBER 2026
Critical Magento Vulnerability CVE-2026-75650: Rust Backdoor and PHP Web ShellAdobe Commerce and Magento Open Source have a critical flaw, CVE-2026-75650, actively exploited to deploy a Rust backdoor and PHP web shell.
EARLY WARNINGNPMSEPTEMBER 2026
Critical Vulnerability in @sap/cds-mtxs NPM Library: Early WarningEarly warning of a critical vulnerability in the @sap/cds-mtxs NPM library that could allow unauthenticated attackers to obtain sensitive credentials.
EARLY WARNINGNPMSEPTEMBER 2026
EPP Processing Library Memory Safety Vulnerability: Early WarningEarly warning of a critical memory safety vulnerability in the EPP processing library. Monitor for updates.
CONFIRMEDCISA_KEVSEPTEMBER 2026
CVE-2026-85880: Microsoft Windows Privilege Escalation VulnerabilityMicrosoft Windows Advanced Local Procedure Call has a heap-based buffer overflow vulnerability allowing privilege escalation.
EARLY WARNINGCISA_KEVSEPTEMBER 2026
N-able N-central Pre-Auth RCE Vulnerability: Early WarningEarly warning of a high-severity pre-authentication RCE vulnerability in N-able N-central.
CONFIRMEDCISA_KEVSEPTEMBER 2026
CVE-2026-81963: Microsoft Windows Update Stack Privilege EscalationConfirmed high severity vulnerability in Microsoft Windows Update Stack allows local privilege escalation.
EARLY WARNINGNPMSEPTEMBER 2026
knowns npm Package Vulnerability: Critical Risk of Unauthorized File WritesEarly warning of a critical vulnerability in knowns npm package allowing unauthorized file writes.
CONFIRMEDNPMSEPTEMBER 2026
Adobe Commerce Critical Vulnerability CVE-2026-75650: What You Need to KnowAdobe Commerce is affected by a critical vulnerability that could allow arbitrary code execution.
EARLY WARNINGNPMSEPTEMBER 2026
Next4Biz CSM Package Vulnerability: Early Warning IssuedEarly warning of a critical deserialization vulnerability in Next4Biz CSM package. Assess your exposure now.
EARLY WARNINGWORDPRESSSEPTEMBER 2026
Frontend Admin by DynamiApps WordPress Plugin Vulnerability AlertEarly warning of a critical vulnerability in the Frontend Admin by DynamiApps WordPress plugin.
EARLY WARNINGNPMSEPTEMBER 2026
WWBN AVideo Path Traversal Vulnerability: Early WarningEarly warning of a critical path traversal vulnerability in WWBN AVideo that allows unauthenticated file writes.
EARLY WARNINGWORDPRESSSEPTEMBER 2026
Elementor Pro WordPress Plugin Vulnerability Exploited to Hack SitesEarly warning: Elementor Pro WordPress plugin has an arbitrary file upload vulnerability that has been exploited to hack sites.
EARLY WARNINGNPMSEPTEMBER 2026
Lara Dashboard Authentication Bypass Vulnerability: Early WarningEarly warning of a critical authentication bypass vulnerability in Lara Dashboard versions before 1.3.0.
EARLY WARNINGWORDPRESSSEPTEMBER 2026
Mail Mint WordPress Plugin Vulnerable to PHP Object InjectionEarly warning: Mail Mint WordPress plugin <=1.31.0 is vulnerable to PHP Object Injection. Upgrade to version 1.23.1 or higher.
EARLY WARNINGNPMSEPTEMBER 2026
Cua computer-server Vulnerability: Critical Authentication BypassEarly warning of a critical vulnerability in cua computer-server versions before 0.3.42.
EARLY WARNINGWORDPRESSSEPTEMBER 2026
Post Grid and Gutenberg Blocks Plugin Vulnerability: Early WarningEarly warning of a critical vulnerability in Post Grid and Gutenberg Blocks plugin for WordPress.
EARLY WARNINGWORDPRESSSEPTEMBER 2026
Critical Vulnerability in Hummingbird WordPress Plugin: Early WarningEarly warning of a critical vulnerability in the Hummingbird WordPress plugin. Assess your exposure now.
EARLY WARNINGWORDPRESSSEPTEMBER 2026
Mstore Api WordPress Plugin Vulnerable to Authentication BypassEarly warning: Mstore Api WordPress plugin up to 4.20.0 is vulnerable to Authentication Bypass via JWT Forgery.
EARLY WARNINGGOSEPTEMBER 2026
OpenChoreo cluster-gateway Vulnerability: Early WarningEarly warning of a high-severity vulnerability in OpenChoreo cluster-gateway that may allow secret disclosure and Kubernetes mutation.
EARLY WARNINGPYPISEPTEMBER 2026
vLLM Package Vulnerability: ReDoS Attack via lm-format-enforcer BackendEarly warning of a high severity vulnerability in vLLM package due to ReDoS attack via lm-format-enforcer backend.
EARLY WARNINGGOSEPTEMBER 2026
SiYuan Package Vulnerability: Session-Cookie Key ExposureEarly warning of a high-severity vulnerability in SiYuan package exposing session-cookie signing key.
EARLY WARNINGNPMSEPTEMBER 2026
SurrealDB Permissions Bypass Vulnerability: Early WarningEarly warning of a high-severity vulnerability in SurrealDB versions before 3.2.0.
EARLY WARNINGNPMSEPTEMBER 2026
SurrealDB Vulnerability: Namespace/Database Scope Override via URL PathEarly warning of a vulnerability in SurrealDB that allows authenticated users to override namespace/database scope via URL path.
EARLY WARNINGCARGOSEPTEMBER 2026
CodeWhale Arbitrary File Read Vulnerability: Early WarningEarly warning of a high-severity vulnerability in CodeWhale that allows arbitrary file read.
EARLY WARNINGCARGOSEPTEMBER 2026
CodeWhale Package Vulnerability: SSRF Bypass Due to DNS Pinning FailureEarly warning of a high-severity vulnerability in CodeWhale package versions before 0.8.64.
EARLY WARNINGCARGOSEPTEMBER 2026
CodeWhale Package Vulnerability: Potential Privilege Escalation RiskEarly warning of a potential privilege escalation vulnerability in CodeWhale package versions before 0.8.64.
EARLY WARNINGNPMSEPTEMBER 2026
SadTalker npm Package OS Command Injection Vulnerability WarningEarly warning of a critical OS command injection vulnerability in SadTalker npm package versions 0.0.1 and 0.0.2.
EARLY WARNINGNPMSEPTEMBER 2026
FastChat Authentication Bypass Vulnerability: Early WarningEarly warning of a critical authentication bypass vulnerability in FastChat npm package.
EARLY WARNINGNPMSEPTEMBER 2026
TEN Framework 0.11.71: Critical Unauthenticated File Access VulnerabilityEarly warning of a critical vulnerability in TEN Framework 0.11.71 allowing unauthenticated file access.
CONFIRMEDNPMSEPTEMBER 2026
marker npm Package Path Traversal Vulnerability: CVE-2026-85684Critical path traversal vulnerability in marker npm package versions up to 2.0.0. Upgrade now.
EARLY WARNINGNPMSEPTEMBER 2026
zerox npm Package OS Command Injection Vulnerability: Early WarningEarly warning of a critical OS command injection vulnerability in zerox npm package version 1.1.20.
EARLY WARNINGNPMSEPTEMBER 2026
xiaobei npm Package Vulnerability: Critical CVE-2026-85667 AlertEarly warning for xiaobei npm package vulnerability CVE-2026-85667. Critical severity, CVSS 9.1. Upgrade recommended.
EARLY WARNINGNPMSEPTEMBER 2026
Aim npm Package Authentication Flaw: Critical CVE-2026-85663Early warning: Aim npm package versions from v0.1.0 to v3.29.1 have a critical authentication flaw.
EARLY WARNINGNPMSEPTEMBER 2026
excel-mcp-server npm Package Vulnerability: Critical CVE-2026-85661Early warning of a critical vulnerability in excel-mcp-server npm package version 0.1.8. CVE-2026-85661 allows arbitrary file access.
EARLY WARNINGPOSTGRESSEPTEMBER 2026
PostgreSQL Vulnerability CVE-2026-6471: Critical Security UpdatePostgreSQL has patched a 12-year-old vulnerability that allows code execution and superuser access.
EARLY WARNINGWORDPRESSSEPTEMBER 2026
Critical Flaws in Super Forms and Elementor Pro Under Active AttackEarly warning of critical security flaws in WordPress plugins Super Forms and Elementor Pro.
CONFIRMEDNPMSEPTEMBER 2026
V8 npm Package Vulnerability CVE-2026-85046: Active ExploitationV8 npm package has a high-severity vulnerability CVE-2026-85046 actively exploited in the wild. Upgrade to the latest version to mitigate risk.
EARLY WARNINGWORDPRESSSEPTEMBER 2026
ACPT (Premium) WordPress Plugin Vulnerability: Critical Privilege EscalationEarly warning of a critical vulnerability in ACPT (Premium) WordPress plugin <=2.0.66. Upgrade now.
EARLY WARNINGWORDPRESSSEPTEMBER 2026
Divi Ajax Filter WordPress Plugin Vulnerable to Local File InclusionEarly warning: Divi Ajax Filter plugin for WordPress is vulnerable to Local File Inclusion in versions <=5.1.2.
EARLY WARNINGNPMSEPTEMBER 2026
SmartIT Desktop Manager Vulnerability: Use of Hard-coded CredentialsEarly warning of a critical vulnerability in SmartIT Desktop Manager. Learn about the use of hard-coded credentials and how to mitigate the risk.
CONFIRMEDNPMSEPTEMBER 2026
CVE-2026-85046: Critical Chromium V8 Type Confusion VulnerabilityGoogle Chromium V8 contains a type confusion vulnerability that allows a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page.
EARLY WARNINGNPMSEPTEMBER 2026
essential-moos npm Package Authorization Flaw: Early WarningEarly warning of a critical authorization flaw in essential-moos npm package <=10.0.1.
CONFIRMEDNPMSEPTEMBER 2026
moos-ivp npm Package Remote Code Execution VulnerabilityCritical remote code execution vulnerability in moos-ivp npm package versions <=24.8.1
EARLY WARNINGNPMSEPTEMBER 2026
core-moos npm Package Authentication Flaw: Critical CVE-2026-85424Early warning of a critical vulnerability in core-moos npm package <=10.4.0. Authentication flaw allows full privilege access.
EARLY WARNINGGOSEPTEMBER 2026
SiYuan Go Package Vulnerability: Database Schema DisclosureEarly warning: SiYuan Go package <= 0.0.0-20260313024916-fd6526133bb3 has a vulnerability that discloses database column schema.
EARLY WARNINGGOSEPTEMBER 2026
SiYuan Go Package Missing Access Checks: Early WarningEarly warning of missing publish-access checks in SiYuan Go package, potentially disclosing protected document content and metadata.
EARLY WARNINGGOSEPTEMBER 2026
SiYuan Go Package Vulnerability: Missing Publish-Access ChecksEarly warning: SiYuan Go package has missing publish-access checks, potentially disclosing protected document content and metadata.
EARLY WARNINGGOSEPTEMBER 2026
SiYuan Vulnerability: Unauthorized Access to Sensitive ContentEarly warning of a vulnerability in SiYuan allowing unauthorized access to sensitive content.
EARLY WARNINGGOSEPTEMBER 2026
SiYuan Package Vulnerabilities: SQL Injection and REGEXP InjectionEarly warning of unauthenticated SQL execution and REGEXP injection in SiYuan package. Assess your exposure now.
EARLY WARNINGGOSEPTEMBER 2026
SiYuan Arbitrary SQL Execution Vulnerability: Early WarningSiYuan application's /api/search/searchEmbedBlock endpoint allows unauthenticated arbitrary SQL execution.
EARLY WARNINGGOSEPTEMBER 2026
amqp091-go Library Vulnerability: Memory Exhaustion RiskEarly warning of a potential memory exhaustion vulnerability in amqp091-go library. Monitor for updates and consider alternatives.
EARLY WARNINGGOSEPTEMBER 2026
amqp091-go Library Vulnerability: Memory Exhaustion RiskEarly warning of a potential memory exhaustion vulnerability in amqp091-go library.
EARLY WARNINGPYPISEPTEMBER 2026
Critical Vulnerability in python-jose Package: Early WarningEarly warning of a critical vulnerability in python-jose package versions up to 3.5.0. Upgrade now.
EARLY WARNINGNPMSEPTEMBER 2026
Peppermint npm Package Under Investigation for Hardcoded JWT SecretEarly warning: peppermint npm package versions 0.1 to 0.5.5 may contain a hardcoded JWT secret.
EARLY WARNINGNPMSEPTEMBER 2026
R2R npm Package Vulnerability: Critical SQL Injection RiskEarly warning of a critical SQL injection vulnerability in R2R npm package versions <=3.6.6.
EARLY WARNINGNPMSEPTEMBER 2026
Orval npm Package Vulnerability: Import-time RCE RiskOrval npm package versions below 8.21.0 may be vulnerable to import-time remote code execution due to improper handling of array-items default values.
EARLY WARNINGNPMSEPTEMBER 2026
Orval npm Package Vulnerability: Remote Code Execution RiskEarly warning of a critical vulnerability in orval npm package that may lead to remote code execution.
EARLY WARNINGNPMSEPTEMBER 2026
Orval npm Package Vulnerability: RCE Risk via MSW MocksEarly warning of a high-severity vulnerability in orval npm package that could lead to remote code execution.
EARLY WARNINGNPMSEPTEMBER 2026
Orval npm Package Vulnerability: Import-Time RCE WarningEarly warning: Orval npm package under 8.21.0 may be vulnerable to import-time RCE.
EARLY WARNINGPYPISEPTEMBER 2026
Server-Side Request Forgery in unstructured: What You Need to KnowEarly warning on a high-severity SSRF vulnerability in unstructured. Learn how it affects you and what to do.
EARLY WARNINGPYPISEPTEMBER 2026
High-Severity SSRF Vulnerability in unstructured Python PackageEarly warning of a high-severity SSRF vulnerability in the unstructured Python package. Learn about the risk and how to mitigate it.
EARLY WARNINGPYPISEPTEMBER 2026
Server-Side Request Forgery in unstructured Python PackageEarly warning of a critical vulnerability in the unstructured Python package. Upgrade to a secure version.
EARLY WARNINGNPMSEPTEMBER 2026
Critical Vulnerability in Taipy npm Package: CVE-2026-85183Early warning of a critical vulnerability in the Taipy npm package. Assess your exposure and take action now.
EARLY WARNINGMAVENSEPTEMBER 2026
CAT Session Cookie Integrity Check Vulnerability: Early WarningEarly warning of a critical vulnerability in CAT's session cookie integrity check mechanism.
EARLY WARNINGWORDPRESSSEPTEMBER 2026
Elementor Pro WordPress Plugin Under Attack: Critical Vulnerability ExploitedEarly warning: Elementor Pro WordPress plugin vulnerability (CVE-2026-32475) exploited in the wild. Upgrade now.
EARLY WARNINGNPMSEPTEMBER 2026
WWBN AVideo Authentication Failure Vulnerability: Early WarningEarly warning of a critical authentication failure vulnerability in WWBN AVideo.
EARLY WARNINGGITHUB-ACTIONSSEPTEMBER 2026
OpenChoreo Workflow Plane Templates: Authenticated OS Command InjectionEarly warning of a high severity vulnerability in OpenChoreo Workflow Plane templates that could allow authenticated users to execute arbitrary commands.
EARLY WARNINGNPMSEPTEMBER 2026
OpenChoreo API Vulnerability: Cross-Project Command Execution RiskEarly warning of a high-severity vulnerability in OpenChoreo API allowing cross-project command execution and wirelog access.
EARLY WARNINGNPMSEPTEMBER 2026
OpenChoreo API Vulnerability: Cross-Project Access RiskEarly warning of a critical vulnerability in OpenChoreo API allowing cross-project command execution and log access.
EARLY WARNINGGOSEPTEMBER 2026
OpenChoreo Cluster-Gateway Vulnerability: Early WarningEarly warning of a vulnerability in OpenChoreo cluster-gateway allowing unauthenticated data-plane operations.
EARLY WARNINGNPMSEPTEMBER 2026
Potential SSRF Vulnerability in @platejs/docx-io npm PackageEarly warning of a potential SSRF vulnerability in @platejs/docx-io npm package. Upgrade to version 53.3.2 or later.
CONFIRMEDGEMSEPTEMBER 2026
Ruby mail Gem Vulnerability: Email Spoofing RiskConfirmed vulnerability in Ruby mail gem allows email address spoofing. Upgrade and sanitize headers.
EARLY WARNINGGEMSEPTEMBER 2026
mail::utilities RubyGem Vulnerability: Email Spoofing RiskEarly warning of a high-severity vulnerability in mail::utilities that may enable email address spoofing.
EARLY WARNINGPYPISEPTEMBER 2026
Omnigent Package Vulnerability: Authenticated RCE RiskEarly warning of a high-severity vulnerability in omnigent package versions < 0.3.0.
EARLY WARNINGNPMSEPTEMBER 2026
submariner npm Package Vulnerability: Critical CVE-2026-66786 AlertEarly warning of a critical flaw in submariner npm package. Potential for remote code execution as root.
CONFIRMEDNPMSEPTEMBER 2026
JFrog Artifactory Authentication Bypass: Critical Vulnerability CVE-2026-82329Critical authentication bypass vulnerability in JFrog Artifactory is being exploited to forge admin tokens.
EARLY WARNINGPYPISEPTEMBER 2026
NLTK PyPI Package SSRF Vulnerability: Early WarningEarly warning of a SSRF vulnerability in NLTK PyPI package versions >= 3.8, <= 3.8 and others.
EARLY WARNINGNPMSEPTEMBER 2026
fastify npm Package Vulnerability: X-Forwarded-* Spoofing RiskEarly warning of a high-severity vulnerability in fastify npm package. Learn about the X-Forwarded-* spoofing risk and how to mitigate it.
EARLY WARNINGNPMSEPTEMBER 2026
Orval npm Package Vulnerability: Import-time RCE via Schema PropertyEarly warning of a high-severity vulnerability in the orval npm package that could lead to import-time remote code execution.
EARLY WARNINGGOSEPTEMBER 2026
SeaweedFS IAM gRPC Service Vulnerability: Critical CVE AlertEarly warning of a critical vulnerability in SeaweedFS IAM gRPC service. Upgrade to version 4.24 and configure JWT signing keys.
EARLY WARNINGGITHUB-ACTIONSSEPTEMBER 2026
SeaweedFS IAM gRPC Service Vulnerability: Early WarningEarly warning of a critical vulnerability in SeaweedFS IAM gRPC service. Upgrade to version 4.24 to mitigate.
EARLY WARNINGNPMSEPTEMBER 2026
qs npm Package Vulnerability: Denial of Service ThreatEarly warning of a Denial of Service vulnerability in the qs npm package. Assess your exposure now.
EARLY WARNINGNPMSEPTEMBER 2026
qs npm Package Vulnerability: Denial of Service RiskEarly warning of a denial of service vulnerability in qs npm package versions >= 2.2.5, < 6.16.0.
EARLY WARNINGGOSEPTEMBER 2026
Siyuan Go Package Vulnerability: Authenticated Path TraversalEarly warning of a critical authenticated path traversal vulnerability in the Siyuan Go package.
EARLY WARNINGGOSEPTEMBER 2026
Siyuan Go Package Vulnerability: Authenticated Path TraversalSiyuan Go package has an authenticated path traversal vulnerability that leaks secrets. Versions <= v3.6.5 are affected.
CONFIRMEDNPMSEPTEMBER 2026
SiYuan <= v3.8.1 Cross-Site Scripting Vulnerability: Upgrade NowSiYuan before v3.8.2 has a stored XSS vulnerability due to an incomplete extension blocklist. Upgrade to v3.8.2 or later.
EARLY WARNINGWORDPRESSSEPTEMBER 2026
SigmaForms Pro WordPress Plugin Vulnerable to Arbitrary File DeletionEarly warning of a critical vulnerability in SigmaForms Pro WordPress plugin <=1.4.11.
EARLY WARNINGWORDPRESSSEPTEMBER 2026
Amelia (Premium) WordPress Plugin Privilege Escalation VulnerabilityEarly warning of a critical vulnerability in Amelia (Premium) WordPress plugin versions 8.0, 9.6.2.
EARLY WARNINGNPMSEPTEMBER 2026
BerriAI LiteLLM npm Package Vulnerability: CVE-2026-59822Early warning: improper authentication vulnerability in BerriAI LiteLLM npm package.
CONFIRMEDNPMSEPTEMBER 2026
Critical Sangoma Switchvox SQL Injection Vulnerability ExploitedSangoma Switchvox contains a critical SQL injection vulnerability allowing remote code execution.
CONFIRMEDCISA_KEVSEPTEMBER 2026
SonicWall SMA1000 Appliances OS Command Injection VulnerabilityHigh severity vulnerability in SonicWall SMA1000 Appliances allows remote code execution.
CONFIRMEDNPMSEPTEMBER 2026
JFrog Artifactory Authentication Bypass: Critical Vulnerability ExploitedJFrog Artifactory contains a critical improper authentication vulnerability (CVE-2026-82329) that is being exploited in the wild.
EARLY WARNINGNPMSEPTEMBER 2026
WWBN AVideo Vulnerability: Critical Security Controls BypassedEarly warning of a critical vulnerability in WWBN AVideo that bypasses security controls using User-Agent header manipulation.
EARLY WARNINGNPMSEPTEMBER 2026
Langflow npm Package Under Attack: Critical Flaw ExploitedEarly warning of a critical vulnerability in Langflow npm package being exploited in attacks on AI platforms.
EARLY WARNINGPYPISEPTEMBER 2026
NLTK Package Vulnerability: JVM Argument Injection BypassEarly warning of a vulnerability in NLTK package allowing JVM argument injection.
EARLY WARNINGPYPISEPTEMBER 2026
Django REST Framework: Potential Bypass of DATA_UPLOAD_MAX_MEMORY_SIZEEarly warning: Django REST Framework may bypass Django's DATA_UPLOAD_MAX_MEMORY_SIZE for oversized JSON and urlencoded request bodies.
EARLY WARNINGPYPISEPTEMBER 2026
Django REST Framework: Bypass of Django DATA_UPLOAD_MAX_MEMORY_SIZEEarly warning about a potential bypass of Django DATA_UPLOAD_MAX_MEMORY_SIZE in Django REST Framework.
EARLY WARNINGNPMSEPTEMBER 2026
MySQL2 Vulnerability: Potential Plaintext Credential LeakEarly warning of a high-severity vulnerability in mysql2 that may leak plaintext credentials.
EARLY WARNINGNPMSEPTEMBER 2026
mysql2 npm Package Vulnerability: Potential Plaintext Credential LeakEarly warning of a vulnerability in mysql2 npm package that may leak plaintext credentials.
EARLY WARNINGNPMSEPTEMBER 2026
Critical SQL Injection Vulnerability in TRtek Technological Products's StoreEarly warning of a critical SQL injection vulnerability affecting TRtek Technological Products's Store.
EARLY WARNINGNPMSEPTEMBER 2026
Kyverno Policy Exception Handling Flaw: Critical CVE-2026-84200 AlertEarly warning of a critical flaw in Kyverno versions v1.9.0 through v1.12.7. Upgrade to v1.13.0 to mitigate.
EARLY WARNINGWORDPRESSSEPTEMBER 2026
Nokri Job Board WordPress Theme Privilege Escalation VulnerabilityEarly warning of a critical vulnerability in Nokri Job Board WordPress Theme <=1.6.6
CONFIRMEDNPMSEPTEMBER 2026
Langflow npm Package Critical Vulnerability: CVE-2026-0768 ExploitedLangflow npm package has a critical security defect allowing remote code execution. CVE-2026-0768 is actively exploited.
CONFIRMEDNPMSEPTEMBER 2026
JFrog Artifactory Authentication Bypass: Critical Vulnerability ExploitedJFrog Artifactory has a critical authentication bypass vulnerability (CVE-2026-82329) that is being actively exploited.
EARLY WARNINGWORDPRESSSEPTEMBER 2026
WPLP Cookie Consent WordPress Plugin Vulnerability: Early WarningEarly warning of a critical vulnerability in WPLP Cookie Consent WordPress plugin <=4.4.1.
EARLY WARNINGNPMAUGUST 2026
Dokploy <=0.29.7 Vulnerability: Path Traversal Exploit in WildEarly warning of a critical vulnerability in Dokploy <=0.29.7. Path traversal exploit now public. Upgrade and review configurations.
EARLY WARNINGNPMAUGUST 2026
ToolJet Vulnerability CVE-2026-82872: Critical Risk of Unauthorized DB AccessEarly warning of a critical vulnerability in ToolJet versions before 1.27.0. Upgrade to v3.16.208 or later.
EARLY WARNINGNPMAUGUST 2026
ToolJet Database Write Vulnerability: Critical CVE-2026-82870 AlertToolJet before v3.16.208 has a critical vulnerability allowing unauthorized database modifications.
EARLY WARNINGNPMAUGUST 2026
Critical Vulnerability in @hulumi/policies npm Package: Early WarningEarly warning of a critical vulnerability in @hulumi/policies npm package versions before 1.3.2.
EARLY WARNINGNPMAUGUST 2026
Critical Vulnerability in @hulumi/drift npm Package: Early WarningEarly warning of a critical vulnerability in @hulumi/drift npm package versions before 1.3.2.
CONFIRMEDNPMAUGUST 2026
Hulumi npm Package Privilege Escalation Vulnerability: CVE-2026-82857Critical privilege escalation vulnerability in Hulumi npm package versions before v1.3.2.
CONFIRMEDNPMAUGUST 2026
Critical Evidence Validation Bypass in @hulumi/policies npm PackageConfirmed critical vulnerability in @hulumi/policies npm package versions before 1.3.2. Upgrade now.
EARLY WARNINGNPMAUGUST 2026
Nodemailer npm Package Vulnerability: Critical SMTP Injection RiskEarly warning of a critical vulnerability in Nodemailer npm package allowing SMTP command injection.
CONFIRMEDCISA_KEVAUGUST 2026
PaperCut NG/MF Vulnerability CVE-2026-81578 Exploited in the WildCritical vulnerability in PaperCut NG/MF allows remote code execution. Upgrade now.
EARLY WARNINGWORDPRESSAUGUST 2026
MyHome Core WordPress Plugin Vulnerable to Authentication BypassEarly warning: MyHome Core WordPress plugin <=4.4.5 is vulnerable to Authentication Bypass. Upgrade once a patch is available.
EARLY WARNINGWORDPRESSAUGUST 2026
Custom User Registration Fields for WooCommerce Plugin Vulnerability AlertEarly warning of a critical vulnerability in Custom User Registration Fields for WooCommerce plugin for WordPress.
EARLY WARNINGNPMAUGUST 2026
Cloud Commander npm Package Directory Traversal Vulnerability AlertCloud Commander npm package versions before 19.20.2 contain a directory traversal vulnerability.
EARLY WARNINGNPMAUGUST 2026
argocd-mcp npm Package Vulnerability: Critical CVE-2026-82456 AlertEarly warning of a critical vulnerability in argocd-mcp npm package version 0.8.0. Assess your exposure now.
EARLY WARNINGNPMAUGUST 2026
Omnivore API Authentication Bypass Vulnerability: Early WarningEarly warning of a critical vulnerability in Omnivore API affecting Apple sign-in token verification.
EARLY WARNINGCARGOAUGUST 2026
Critical Authentication Bypass in rust-iot-platform: What We KnowEarly warning of a critical authentication bypass vulnerability in rust-iot-platform.
EARLY WARNINGNPMAUGUST 2026
Shinobi npm Package Vulnerability: Critical CVE-2026-82448 AlertEarly warning for a critical vulnerability in Shinobi npm package. Learn about the potential risks and recommended actions.
EARLY WARNINGWORDPRESSAUGUST 2026
Sigma Forms Pro WordPress Plugin Vulnerable to Remote Code ExecutionEarly warning of a critical vulnerability in Sigma Forms Pro WordPress plugin. Assess your exposure now.
CONFIRMEDNPMAUGUST 2026
@7nohe/openapi-react-query-codegen npm Package CompromisedTen malicious versions of @7nohe/openapi-react-query-codegen were published through an exposed npm publishing workflow.
EARLY WARNINGGOAUGUST 2026
free5GC AUSF Authentication Contexts Vulnerability: Early WarningEarly warning of a vulnerability in free5GC AUSF component that could lead to authentication denial of service.
EARLY WARNINGGITHUB-ACTIONSAUGUST 2026
SeaweedFS S3 API Path Traversal Vulnerability: Early WarningEarly warning of a path traversal vulnerability in SeaweedFS S3 API that could allow cross-bucket object read.
EARLY WARNINGGITHUB-ACTIONSAUGUST 2026
SeaweedFS Path Traversal Vulnerability: Early WarningEarly warning of a path traversal vulnerability in SeaweedFS S3 API gateway.
EARLY WARNINGNPMAUGUST 2026
IBM Langflow OSS Vulnerability: Critical CVE-2026-19295 AlertEarly warning of a critical vulnerability in IBM Langflow OSS versions 1.0.0 through 1.11.1. Upgrade or apply workarounds.
EARLY WARNINGNPMAUGUST 2026
IBM Langflow OSS Vulnerability: Critical CVE-2026-19286 AlertEarly warning of a critical vulnerability in IBM Langflow OSS versions 1.0.0 through 1.11.1. Upgrade or apply a patch if available.
EARLY WARNINGNPMAUGUST 2026
mariadb connector/node.js Cleartext Transmission Vulnerability AlertEarly warning of a vulnerability in mariadb connector/node.js that may transmit sensitive information in cleartext.
EARLY WARNINGNPMAUGUST 2026
Critical Cosmos EVM Flaw Exploited: Funds Drained from Six BlockchainsEarly warning of a critical balance-handling flaw in Cosmos EVM exploited to drain funds from six blockchains.
EARLY WARNINGNPMAUGUST 2026
Argo Rollouts Dashboard Vulnerability: Critical CVE-2026-82277 AlertEarly warning for a critical vulnerability in Argo Rollouts dashboard versions up to 1.10.0.
EARLY WARNINGPACKAGISTAUGUST 2026
Pimcore Vulnerability: Remote Code Execution and SQL Injection RiskEarly warning of a critical vulnerability in Pimcore that may allow remote code execution and SQL injection.
EARLY WARNINGPACKAGISTAUGUST 2026
Pimcore Hotspotimage Component Vulnerability: Early WarningEarly warning of a high-severity vulnerability in Pimcore Hotspotimage component leading to potential remote code execution.
EARLY WARNINGPYPIAUGUST 2026
plone.app.event Denial of Service and Stored XSS VulnerabilityEarly warning of a high-severity vulnerability in plone.app.event that could lead to denial of service and stored XSS.
EARLY WARNINGPYPIAUGUST 2026
Weblate IDOR Vulnerability: Assess Your Exposure NowEarly warning of an IDOR vulnerability in Weblate's GroupViewSet. Check your version.
EARLY WARNINGPYPIAUGUST 2026
plone.app.portlets Package Vulnerability: Denial of Service ThreatEarly warning of a denial of service vulnerability in plone.app.portlets via RSS feed portlet. Upgrade to patched versions.
EARLY WARNINGCARGOAUGUST 2026
Buffa Protobuf Decoder Vulnerable to Memory ExhaustionEarly warning of a high-severity vulnerability in buffa's protobuf decoder that could lead to memory exhaustion.
EARLY WARNINGCARGOAUGUST 2026
High-Severity Soundness Bug in buffa's OwnedViewEarly warning of a high-severity soundness bug in buffa's OwnedView that can lead to memory corruption and information disclosure.
EARLY WARNINGPYPIAUGUST 2026
piccolo-admin Privilege Escalation Issue: Early WarningEarly warning of a privilege escalation issue in piccolo-admin allowing admin impersonation.
EARLY WARNINGMAVENAUGUST 2026
Yamcs Vulnerable to Authenticated Remote Code ExecutionEarly warning: Yamcs is under investigation for a critical vulnerability allowing remote code execution.
CONFIRMEDCISA_KEVAUGUST 2026
PaperCut NG/MF Vulnerability CVE-2026-82078 Exploited in the WildMalicious actors exploit PaperCut NG/MF flaw to execute code. Upgrade now.
EARLY WARNINGMAVENAUGUST 2026
Yamcs Vulnerable to Authenticated RCE via StreamSQL InjectionYamcs is reportedly vulnerable to authenticated RCE via StreamSQL injection. Assess your exposure now.
EARLY WARNINGMAVENAUGUST 2026
Yamcs Vulnerable to Authenticated Remote Code ExecutionYamcs is reportedly vulnerable to authenticated remote code execution via injection flaws.
EARLY WARNINGMAVENAUGUST 2026
Yamcs Vulnerable to Authenticated Remote Code ExecutionYamcs is reportedly vulnerable to authenticated remote code execution via an injection flaw.
EARLY WARNINGGOAUGUST 2026
Vikunja Package Vulnerability: Incomplete Fix for CVE-2026-35595Early warning of a vulnerability in Vikunja package due to an incomplete fix for CVE-2026-35595.
EARLY WARNINGGOAUGUST 2026
Vikunja Package Vulnerability: Incomplete Fix for CVE-2026-35595Early warning of a vulnerability in the Vikunja package due to an incomplete fix for CVE-2026-35595.
EARLY WARNINGCARGOAUGUST 2026
datadog-opentelemetry Crate Vulnerability: Unbounded W3C Tracestate ParsingEarly warning of a high-severity vulnerability in datadog-opentelemetry crate that may lead to DoS.
EARLY WARNINGCARGOAUGUST 2026
datadog-opentelemetry Package Vulnerability: What You Need to KnowEarly warning of a potential DoS vulnerability in datadog-opentelemetry due to unbounded W3C tracestate parsing.
EARLY WARNINGNPMAUGUST 2026
Pocket-ID Frontend Open Redirect VulnerabilityAn open redirect vulnerability in Pocket-ID frontend may allow phishing and OAuth response smuggling.
EARLY WARNINGNPMAUGUST 2026
Pocket-ID OIDC Vulnerability Under InvestigationAn open redirect vulnerability in Pocket-ID OIDC /authorize page is under investigation. Upgrade to the latest version.
EARLY WARNINGGOAUGUST 2026
Klever Go Package Vulnerability: Integer Overflow RiskEarly warning of an integer overflow vulnerability in Klever Go package that may enable unbounded minting of KLV tokens.
EARLY WARNINGGOAUGUST 2026
Klever Go Package Compromised: What We KnowEarly warning of a high-severity supply-chain attack on the Klever Go package. Assess your exposure now.
EARLY WARNINGCARGOAUGUST 2026
gix-packetline Crate Vulnerability: Denial of Service RiskEarly warning of a potential denial of service vulnerability in the gix-packetline Rust crate.
EARLY WARNINGCARGOAUGUST 2026
gix-packetline Rust Crate Vulnerability: Early WarningEarly warning for a vulnerability in the gix-packetline Rust crate that may lead to denial of service.
EARLY WARNINGLINUXAUGUST 2026
Linux Kernel Flaw CVE-2026-53362 Exploited by OpenAI AgentsEarly warning: Linux kernel flaw CVE-2026-53362 reportedly exploited by OpenAI agents on company systems.
EARLY WARNINGNPMAUGUST 2026
Budibase Remote Code Execution Vulnerability: Early WarningEarly warning of a critical remote code execution vulnerability in Budibase versions before 3.41.3.
EARLY WARNINGWORDPRESSAUGUST 2026
WPMU DEV Dashboard WordPress Plugin Vulnerability: Early WarningEarly warning of a critical vulnerability in WPMU DEV Dashboard WordPress plugin. Upgrade to mitigate risk.
EARLY WARNINGNPMAUGUST 2026
Critical Vulnerability in mcp-http-server: What You Need to KnowEarly warning of a critical vulnerability in mcp-http-server package that could allow arbitrary command execution.
CONFIRMEDCAUGUST 2026
openssl_encrypt Package Vulnerability: Critical CVE-2026-81702 ConfirmedConfirmed critical vulnerability in openssl_encrypt package. Upgrade to version 1.4.9 or later.
CONFIRMEDNPMAUGUST 2026
openssl_encrypt npm Package Vulnerability: Critical Signature Bypassopenssl_encrypt npm package versions before 1.4.9 contain a critical signature verification vulnerability.
EARLY WARNINGPYPIAUGUST 2026
ToolUniverse Python Package Vulnerability: Critical CVE-2026-81096Early warning: ToolUniverse Python package has a critical vulnerability allowing remote code execution.
CONFIRMEDNPMAUGUST 2026
Citrix NetScaler Vulnerability CVE-2026-8452 Exploited in the WildHigh-severity Citrix NetScaler vulnerability CVE-2026-8452 is being actively exploited. Upgrade now.
CONFIRMEDNPMAUGUST 2026
Critical JFrog Artifactory Vulnerability Exploited in the WildJFrog Artifactory contains a critical vulnerability that has been exploited in the wild.
EARLY WARNINGNPMAUGUST 2026
ownCloud Improper Authentication Vulnerability Under InvestigationEarly warning: ownCloud contains an improper authentication vulnerability that is reportedly exploited in the wild.
EARLY WARNINGPHPAUGUST 2026
ILIAS Application Vulnerability: Critical Deserialization IssueILIAS application is under investigation for a critical deserialization vulnerability. Assess your exposure now.
EARLY WARNINGPYPIAUGUST 2026
pantheon-agents PyPI Package Compromised: Early WarningEarly warning of a critical supply-chain attack on pantheon-agents PyPI package. Assess your exposure now.
EARLY WARNINGCARGOAUGUST 2026
Wasmtime Vulnerability in WASIp1 `fd_renumber` ImplementationWasmtime has a reported leak in the WASIp1 `fd_renumber` function. Update to patched versions to mitigate.
EARLY WARNINGGOAUGUST 2026
Kyverno v1.18.1 Vulnerability: NamespacedMutatingPolicy RiskEarly warning on Kyverno v1.18.1 vulnerability allowing arbitrary namespace access.
CONFIRMEDGITHUB-ACTIONSAUGUST 2026
Critical Gitea RCE Vulnerability CVE-2026-60004 Actively ExploitedGitea RCE vulnerability CVE-2026-60004 is being actively exploited. Upgrade to version 1.27.1 to mitigate risk.
EARLY WARNINGMAVENAUGUST 2026
Apache Tomcat Authentication Vulnerability: Critical CVE-2026-68525Early warning of a critical vulnerability in Apache Tomcat's FORM authentication process. Upgrade to patched versions to mitigate risk.
EARLY WARNINGCISA_KEVAUGUST 2026
Red Hat ABRT Privilege Escalation Vulnerability: Early WarningEarly warning of a privilege escalation vulnerability in Red Hat ABRT. Assess your exposure and take recommended actions.
EARLY WARNINGCISA_KEVAUGUST 2026
Citrix NetScaler ADC and NetScaler Gateway Vulnerability Under InvestigationEarly warning of a high severity vulnerability in Citrix NetScaler ADC and NetScaler Gateway.
EARLY WARNINGNUGETAUGUST 2026
Microsoft SQL Server Vulnerability CVE-2019-1068: Early WarningEarly warning of a high-severity remote code execution vulnerability in Microsoft SQL Server.
CONFIRMEDCISA_KEVAUGUST 2026
Linux Kernel Vulnerability CVE-2022-0995 Exploited in the WildLinux Kernel contains an out-of-bounds memory write vulnerability exploited in the wild. Upgrade to the latest version.
EARLY WARNINGNPMAUGUST 2026
Critical Vulnerability in ClipBucket V5 Web Installer: CVE-2026-80138Early warning of a critical vulnerability in ClipBucket V5 web installer. CVE-2026-80138 allows unauthenticated command execution.
EARLY WARNINGNPMAUGUST 2026
dbgpt-app npm Package Vulnerability: Critical CVE-2026-80104 AlertEarly warning of a critical vulnerability in dbgpt-app npm package. Learn about the risk and recommended actions.
EARLY WARNINGPYPIAUGUST 2026
Chainlit Package Vulnerability: Command Injection via MCP stdio TransportEarly warning of a critical vulnerability in Chainlit allowing unauthenticated remote code execution.
EARLY WARNINGNPMAUGUST 2026
Alluxio S3 REST Proxy Vulnerability: Critical CVE-2026-79787Early warning of a critical vulnerability in Alluxio's S3 REST proxy. Assess your exposure now.
EARLY WARNINGPYPIAUGUST 2026
NLTK Python Package Vulnerability: JVM Argument Injection RiskEarly warning on NLTK Python package vulnerability allowing JVM argument injection. Upgrade to nltk 3.10.3 or later.
EARLY WARNINGPYPIAUGUST 2026
NLTK Vulnerability: JVM Argument Injection RiskEarly warning about a vulnerability in NLTK that allows JVM argument injection.
EARLY WARNINGGEMAUGUST 2026
Nokogiri Gem Vulnerability: Denial of Service RiskEarly warning of a denial of service vulnerability in Nokogiri gem versions before 1.19.3.
CONFIRMEDGEMAUGUST 2026
Nokogiri Gem Denial-of-Service Vulnerability: Critical CVEsNokogiri gem before 1.13.2 vulnerable to denial-of-service attacks via libxml2 and libxslt.
EARLY WARNINGPYPIAUGUST 2026
nextcloud-mcp-server Package Vulnerability: Critical Endpoint ExposedEarly warning of a critical vulnerability in nextcloud-mcp-server package. Learn how to assess your exposure and mitigate the risk.
EARLY WARNINGNPMAUGUST 2026
TRtek Software Repository Management Vulnerability: Early WarningEarly warning of a critical vulnerability in TRtek Software Repository Management. Upgrade to version 2fb4acee or later.
EARLY WARNINGPYPIAUGUST 2026
PraisonAI async Jobs API Authentication Bypass VulnerabilityPraisonAI async Jobs API has no authentication, allowing unauthenticated job execution and result theft.
EARLY WARNINGPYPIAUGUST 2026
PraisonAI async Jobs API Authentication Bypass: Early WarningEarly warning: PraisonAI async Jobs API has no authentication, allowing unauthenticated job execution and result theft.
EARLY WARNINGPYPIAUGUST 2026
NLTK Remote Code Execution Vulnerability: Early Warning and Mitigation StepsEarly warning about a remote code execution vulnerability in NLTK versions before 3.10.3.
EARLY WARNINGWORDPRESSAUGUST 2026
Total Donations WordPress Plugin Vulnerable to SQL Injection and Privilege EscalationEarly warning: Total Donations plugin for WordPress is vulnerable to critical SQL Injection and Privilege Escalation.
EARLY WARNINGWORDPRESSAUGUST 2026
Jawn WordPress Theme Privilege Escalation VulnerabilityEarly warning of a critical vulnerability in Jawn WordPress theme <=1.4.2.
EARLY WARNINGJAVAAUGUST 2026
Oracle WebLogic Server Flaw CVE-2026-21962 Under Active AttackOracle WebLogic Server is reportedly affected by a critical security flaw that is being actively exploited.
EARLY WARNINGPYPIAUGUST 2026
NLTK versions before 3.10.3 may allow arbitrary code executionEarly warning: NLTK versions before 3.10.3 may be vulnerable to arbitrary code execution due to an uncontrolled search path element.
EARLY WARNINGPYPIAUGUST 2026
NLTK Python Package Vulnerability: Unsafe Pickle DeserializationEarly warning about a critical vulnerability in NLTK Python package. Assess your exposure and take action.
EARLY WARNINGPYPIAUGUST 2026
GitPython Vulnerability: Dormant Config Values Corrupted, RCE RiskGitPython before 3.1.59 may corrupt dormant git-config values, enabling RCE.
EARLY WARNINGPYPIAUGUST 2026
NLTK Pickle Deserialization Vulnerability: Critical CVE-2026-78683Early warning of a critical vulnerability in NLTK versions before 3.10.0. Upgrade to NLTK 3.10.0 or later.
EARLY WARNINGPYPIAUGUST 2026
GitPython Vulnerability CVE-2026-78676: Critical Arbitrary Code Execution RiskEarly warning for GitPython vulnerability CVE-2026-78676. Assess your exposure and upgrade to mitigate risk.
EARLY WARNINGNPMAUGUST 2026
Grav Login Plugin Vulnerability: Critical CVE-2026-56710 AlertEarly warning of a critical vulnerability in Grav Login plugin versions before 1.0.16.
EARLY WARNINGPACKAGISTAUGUST 2026
Adminer Vulnerability CVE-2026-56705: Critical Remote Code Execution RiskAdminer versions before 5.4.3 are reportedly vulnerable to remote code execution due to improper sanitization of the server field.
CONFIRMEDGITHUB-ACTIONSAUGUST 2026
Gitea Code Injection Vulnerability CVE-2026-60004: What You Need to KnowGitea contains a critical code injection vulnerability that allows remote code execution. Upgrade now.
EARLY WARNINGCARGOAUGUST 2026
tokio-postgres Rust Crate Vulnerability: Early WarningEarly warning of a vulnerability in tokio-postgres that can cause panic and task aborts.
EARLY WARNINGCARGOAUGUST 2026
postgres-protocol Crate: Unbounded SCRAM Iteration Count VulnerabilityEarly warning of a denial of service vulnerability in postgres-protocol crate due to unbounded SCRAM iteration count.
EARLY WARNINGCARGOAUGUST 2026
postgres-protocol Crate: Potential CPU-Exhaustion Denial of ServiceEarly warning of a potential denial of service vulnerability in postgres-protocol crate due to unbounded SCRAM iteration count.
EARLY WARNINGPYPIAUGUST 2026
mcp-contextforge-gateway Package Sandbox Bypass Vulnerability AlertEarly warning of a sandbox bypass vulnerability in mcp-contextforge-gateway package.
EARLY WARNINGMAVENAUGUST 2026
Apache Camel Undertow Vulnerability: Improper Input ValidationEarly warning of a high severity improper input validation vulnerability in Apache Camel Undertow component.
EARLY WARNINGMAVENAUGUST 2026
Apache Camel Azure Storage Blob: Path Traversal Vulnerability AlertEarly warning of a critical path traversal vulnerability in Apache Camel Azure Storage Blob component.
EARLY WARNINGMAVENAUGUST 2026
Apache Camel Azure Storage Blob: Path Traversal Vulnerability Under InvestigationEarly warning: Apache Camel Azure Storage Blob has a reported path traversal vulnerability. Upgrade once a fix is available.
EARLY WARNINGGOAUGUST 2026
OAuth2 Proxy Vulnerability: Authentication Bypass RiskEarly warning of a critical vulnerability in OAuth2 Proxy that may allow authentication bypass.
EARLY WARNINGNPMAUGUST 2026
rConfig Authentication Bypass Vulnerability: Early WarningEarly warning of a critical authentication bypass vulnerability in rConfig versions 8.0.0 to 8.2.12.
EARLY WARNINGCARGOAUGUST 2026
Critical Vulnerability in RustDesk Windows Clipboard RedirectionEarly warning of a critical vulnerability in RustDesk's Windows clipboard redirection feature.
EARLY WARNINGNPMAUGUST 2026
exceljs-hardened npm Package Vulnerability: What We Knowexceljs-hardened npm package before version 5.0.0 contains a critical prototype pollution vulnerability.
EARLY WARNINGCISA_KEVAUGUST 2026
Oracle HTTP and WebLogic Servers: Improper Access Control VulnerabilityEarly warning of a high-severity improper access control vulnerability in Oracle HTTP and WebLogic Servers.
EARLY WARNINGNPMAUGUST 2026
justhtml npm Package Vulnerability: Critical CVE-2026-8445 AlertEarly warning for a critical vulnerability in justhtml npm package versions <= 1.11.0. Upgrade to version 1.12.0 to mitigate risk.
CONFIRMEDNPMAUGUST 2026
Critical Security Issues in justhtml npm Package: Upgrade Nowjusthtml npm package before version 1.15.0 contains multiple security issues. Upgrade to mitigate.
EARLY WARNINGWORDPRESSAUGUST 2026
WS Form LITE WordPress Plugin Vulnerable to PHP Object InjectionWS Form LITE WordPress plugin <=1.10.80 is reportedly vulnerable to PHP Object Injection. Upgrade now.
EARLY WARNINGPYPIAUGUST 2026
NLTK Supply-Chain Vulnerability: Early Warning and Mitigation StepsEarly warning of a high-severity supply-chain vulnerability in NLTK. Learn how to assess your exposure and mitigate the risk.
EARLY WARNINGWORDPRESSAUGUST 2026
Mailgun for WordPress Plugin Vulnerable to SSRF Attack: CVE-2026-78003Mailgun for WordPress plugin versions up to 2.2.0 are reportedly vulnerable to Server-Side Request Forgery (SSRF) via path traversal.
EARLY WARNINGNPMAUGUST 2026
JSONata npm Package Vulnerability: Arbitrary Code Execution RiskEarly warning of a high severity vulnerability in JSONata npm package versions before 2.2.1 and 1.8.8.
EARLY WARNINGPYPIAUGUST 2026
Hydra Python Package: Potential Arbitrary Code Execution RiskEarly warning of a high-severity vulnerability in Hydra Python package that may lead to arbitrary code execution.
EARLY WARNINGPYPIAUGUST 2026
Hydra Python Package: Arbitrary Code Execution RiskEarly warning: Hydra Python package's instantiate() function may lead to arbitrary code execution.
EARLY WARNINGNPMAUGUST 2026
jsonata npm Package Vulnerability: Arbitrary Code Execution RiskEarly warning of a high-severity vulnerability in jsonata npm package allowing arbitrary code execution.
EARLY WARNINGPACKAGISTAUGUST 2026
Phalcon Volt Compiler Vulnerability: Critical CVE-2026-59989 AlertEarly warning for a critical vulnerability in Phalcon Volt compiler leading to potential remote code execution.
EARLY WARNINGGITHUB-ACTIONSAUGUST 2026
Atlantis Path Traversal Vulnerability: Upgrade to 0.45.0Atlantis versions >= 0.19.8 and < 0.45.0 have a path traversal vulnerability. Upgrade to 0.45.0.
EARLY WARNINGGITHUB-ACTIONSAUGUST 2026
Atlantis Path Traversal Vulnerability: Upgrade to 0.45.0Early warning: Atlantis versions >= 0.19.8 and < 0.45.0 have a path traversal vulnerability. Upgrade to 0.45.0.
EARLY WARNINGMAVENAUGUST 2026
GeoTools SQL Injection Vulnerability: Early Warning and Mitigation StepsEarly warning of a critical SQL injection vulnerability in GeoTools affecting specific versions.
EARLY WARNINGGEMAUGUST 2026
Paperclip Gem Vulnerability CVE-2026-77087: Early WarningEarly warning for Paperclip gem vulnerability CVE-2026-77087. Learn about the critical issue and recommended actions.
EARLY WARNINGNPMAUGUST 2026
Headroom LLM Proxy Vulnerability: Critical CVE-2026-77776 AlertHeadroom LLM proxy vulnerability allows unauthorized access to user data. Upgrade to latest version and ensure proper authentication.
EARLY WARNINGNPMAUGUST 2026
SiYuan Path Traversal Vulnerability: Critical CVE-2026-77086 AlertEarly warning of a critical path traversal vulnerability in SiYuan versions before 3.7.4. Upgrade to mitigate.
EARLY WARNINGWORDPRESSAUGUST 2026
WordPress Plugin Vulnerability: Authentication Bypass RiskEarly warning of a critical vulnerability in the Automation Web Platform plugin for WordPress.
EARLY WARNINGNPMAUGUST 2026
Microsoft Entra ID Vulnerability CVE-2026-69836: Early WarningEarly warning of a high-severity vulnerability in Microsoft Entra ID, formerly Azure Active Directory, which could allow remote code execution.
CONFIRMEDCISA_KEVAUGUST 2026
CVE-2026-73570: Zimbra Collaboration Suite OS Command Injection ThreatConfirmed high severity threat in Zimbra Collaboration Suite due to OS command injection vulnerability.
EARLY WARNINGNPMAUGUST 2026
EverShop Vulnerability: Public Access to Customer Update RouteEarly warning of a critical vulnerability in EverShop allowing public access to customer update route.
EARLY WARNINGNPMAUGUST 2026
multicloud-operators-subscription Vulnerability: Critical CVE-2026-67567Early warning of a critical vulnerability in multicloud-operators-subscription. Learn about the flaw and recommended actions.
EARLY WARNINGNPMAUGUST 2026
Submariner Vulnerability CVE-2026-66785: Critical Risk AlertEarly warning of a critical vulnerability in Submariner, CVE-2026-66785, potentially allowing network traffic redirection.
EARLY WARNINGMAVENAUGUST 2026
netty-incubator-codec-ohttp Vulnerability: CPU-Exhaustion DoS RiskEarly warning of a high-severity vulnerability in netty-incubator-codec-ohttp that could lead to CPU-exhaustion DoS attacks.
EARLY WARNINGMAVENAUGUST 2026
netty-incubator-codec-ohttp Vulnerability: Early Warning and MitigationEarly warning of a high-severity vulnerability in netty-incubator-codec-ohttp. Learn about the risk and mitigation steps.
EARLY WARNINGMAVENAUGUST 2026
netty-incubator-codec-ohttp-hpke-classes-boringssl Package Vulnerability AlertEarly warning: netty-incubator-codec-ohttp-hpke-classes-boringssl may expose private key bytes.
EARLY WARNINGMAVENAUGUST 2026
netty-incubator-codec-ohttp-hpke-classes-boringssl Vulnerability: Key Exposure RiskEarly warning of a vulnerability in netty-incubator-codec-ohttp-hpke-classes-boringssl exposing private key bytes.
EARLY WARNINGPYPIAUGUST 2026
django CMS Clipboard Copy IDOR Vulnerability: Early WarningEarly warning for a potential IDOR vulnerability in django CMS clipboard copy paths. Upgrade to version 5.0.8 or later.
EARLY WARNINGPYPIAUGUST 2026
django CMS IDOR Vulnerability in Clipboard Copy Paths: Early WarningEarly warning of a potential IDOR vulnerability in django CMS clipboard copy paths. Upgrade to version 5.0.8 or later.
EARLY WARNINGGITHUB-ACTIONSAUGUST 2026
Tekton Pipelines-as-Code GitHub App Token Vulnerability WarningEarly warning: Tekton Pipelines-as-Code GitHub App token may allow unauthorized access to private repositories.
EARLY WARNINGGITHUB-ACTIONSAUGUST 2026
Tekton Pipelines-as-Code Vulnerability: Unauthorized Access RiskEarly warning of a vulnerability in Tekton Pipelines-as-Code that may allow unauthorized access to private repositories.
EARLY WARNINGGOAUGUST 2026
OpenTofu High CPU Usage Vulnerabilities: CVE-2026-27145, CVE-2026-42504Early warning: OpenTofu may experience high CPU usage under certain conditions. Upgrade to v1.11.9 or v1.12.2.
EARLY WARNINGGOAUGUST 2026
Dgraph Alpha Vulnerability: Unauthenticated Snapshot Import RiskDgraph Alpha exposes RPCs for external snapshot import on the public gRPC port without authentication. Assess your exposure now.
CONFIRMEDCARGOAUGUST 2026
Rust Supply-Chain Attack: arrayref and proc-macro1 Crates CompromisedConfirmed supply-chain attack on Rust crates arrayref and proc-macro1. Assess your exposure and take immediate action.
CONFIRMEDNPMAUGUST 2026
GitLab npm Package Critical Vulnerability: CVE-2026-19478 ExploitedGitLab npm package vulnerability CVE-2026-19478 is actively exploited. Upgrade now.
CONFIRMEDNPMAUGUST 2026
TrueConf Server Code Injection Vulnerability: CVE-2026-72530TrueConf Server contains a code injection vulnerability that could allow an unauthorized remote attacker to execute arbitrary code on the host system.
EARLY WARNINGPYPIAUGUST 2026
lmdeploy Package Vulnerability: Critical Remote Code Execution Risklmdeploy package vulnerability allows remote code execution. Check your version and disable disaggregated serving.
EARLY WARNINGNPMAUGUST 2026
ICEcoder 8.1 Remote Code Execution Vulnerability: Early WarningICEcoder 8.1 reportedly contains a critical unauthenticated remote code execution vulnerability.
EARLY WARNINGJAVASCRIPTAUGUST 2026
XWiki Platform Live Data Table Connector Privilege Escalation WarningEarly warning of a privilege escalation vulnerability in XWiki Platform Live Data Table Connector.
EARLY WARNINGJAVASCRIPTAUGUST 2026
XWiki Platform Live Data Table Connector Privilege Escalation VulnerabilityEarly warning: XWiki Platform Live Data Table Connector vulnerability allows privilege escalation.
EARLY WARNINGWORDPRESSAUGUST 2026
TrueBooker WordPress Plugin Vulnerable to Account TakeoverEarly warning: TrueBooker WordPress plugin <=1.2.6 has a critical vulnerability leading to account takeover.
EARLY WARNINGNPMAUGUST 2026
Contentful MCP Tools Vulnerability Under InvestigationContentful MCP tools may pass LLM-controlled host/proxy args to CMA client, redirecting server PAT to attacker-controlled endpoint.
EARLY WARNINGPYPIAUGUST 2026
langgraph-api Vulnerability: Relative Webhook Targets Bypass AuthenticationEarly warning on langgraph-api vulnerability allowing unauthorized access via relative webhook targets.
EARLY WARNINGPYPIAUGUST 2026
langgraph-api Vulnerability: Relative Webhook Targets Bypass AuthenticationEarly warning about a langgraph-api vulnerability allowing unauthorized access via relative webhook targets.
EARLY WARNINGNPMAUGUST 2026
Cluster-Proxy-Addon Vulnerability in Multicluster EngineA critical flaw in cluster-proxy-addon for Kubernetes may allow unauthenticated access. Upgrade and review access controls.
EARLY WARNINGCAUGUST 2026
FFmpeg Heap Buffer Overflow Vulnerability: Early WarningEarly warning of a critical heap buffer overflow vulnerability in FFmpeg before commit 1c10bcc.
EARLY WARNINGNPMAUGUST 2026
search-v2-operator npm Package Vulnerability: Early WarningEarly warning of a critical flaw in search-v2-operator npm package. Potential privilege escalation and cluster compromise.
EARLY WARNINGPYPIAUGUST 2026
Lemur Package Missing Authorization Check: Early WarningEarly warning of a missing authorization check vulnerability in the Lemur package. Learn about the issue and how to assess your exposure.
EARLY WARNINGPYPIAUGUST 2026
Lemur Package Missing Authorization Check Vulnerability AlertLemur package has a missing authorization check vulnerability. Review and update your package.
EARLY WARNINGPACKAGISTAUGUST 2026
Froxlor API Endpoints Disclose Sensitive Authentication DataEarly warning: Froxlor API endpoints expose sensitive authentication material, including password hashes and TOTP 2FA seeds.
EARLY WARNINGPACKAGISTAUGUST 2026
mtdowling/jmespath.php Code Injection Vulnerability: Early WarningEarly warning of a critical code injection vulnerability in mtdowling/jmespath.php. Upgrade to version 2.9.1 or later.
EARLY WARNINGPYPIAUGUST 2026
resdata Package Vulnerability: Buffer Overflow and MoreEarly warning of a high-severity vulnerability in resdata package versions prior to 6.2.9.
EARLY WARNINGGEMAUGUST 2026
kobako Sandbox Escape Vulnerability: Early WarningEarly warning of a high-severity sandbox escape vulnerability in kobako gem versions >= 0.1.0, < 0.9.1.
EARLY WARNINGGEMAUGUST 2026
kobako Sandbox Escape Vulnerability: Early Warning and MitigationEarly warning of a sandbox escape vulnerability in kobako gem. Upgrade to kobako@0.9.1 to mitigate.
EARLY WARNINGNPMAUGUST 2026
Keycloak Reset-Credentials Flaw: Urgent Security Update NeededEarly warning of a high-severity flaw in Keycloak's reset-credentials flow. Update now.
EARLY WARNINGNPMAUGUST 2026
context7 npm Package Vulnerability: Early Warning IssuedEarly warning issued for context7 npm package vulnerability. Assess your exposure and take recommended actions.
EARLY WARNINGPYPIAUGUST 2026
MobSF CSRF Checks Not Enforced After Django MigrationEarly warning: MobSF's CSRF checks are reportedly not enforced after Django migration.
EARLY WARNINGPYPIAUGUST 2026
MobSF CSRF Vulnerability After Django Migration: Early WarningEarly warning about MobSF's CSRF checks not enforced after Django migration. Assess your exposure now.
CONFIRMEDNPMAUGUST 2026
Critical MLflow and FUXA Vulnerabilities Exploited: Cloud Credentials at RiskTwo critical vulnerabilities in MLflow and FUXA are being actively exploited to steal cloud credentials and secrets.
EARLY WARNINGNPMAUGUST 2026
Critical CVE in Keycloak Services: Password Reset VulnerabilityEarly warning of a critical flaw in Keycloak services allowing unauthenticated password resets.
EARLY WARNINGNPMAUGUST 2026
Critical Vulnerability in @rhinostone/swig npm Package: Path TraversalEarly warning of a critical vulnerability in @rhinostone/swig npm package that allows arbitrary local file read.
EARLY WARNINGNPMAUGUST 2026
CodeWhale Vulnerability CVE-2026-75913: Argument Injection RiskEarly warning for CodeWhale versions >= 0.8.41 and < 0.8.64. Argument injection vulnerability in git_show tool.
EARLY WARNINGPYPIAUGUST 2026
Critical Flaw in AAP Controller's HashiCorp Vault PluginEarly warning of a critical flaw in AAP Controller's HashiCorp Vault credential plugin.
EARLY WARNINGNPMAUGUST 2026
ArcadeDB Authentication Bypass: Critical Vulnerability Under InvestigationArcadeDB versions before 26.8.1 may allow unauthenticated database commands. Upgrade to 26.8.1 or later.
EARLY WARNINGNPMAUGUST 2026
ArcadeDB Server <= 26.7.3 Vulnerability: Critical Authorization BypassEarly warning of a critical vulnerability in ArcadeDB server <= 26.7.3 that allows unauthorized admin access.
CONFIRMEDNPMAUGUST 2026
ArcadeDB Critical Vulnerability: Unauthorized JavaScript ExecutionArcadeDB versions before 26.8.1 allow unauthorized JavaScript execution. Upgrade now.
EARLY WARNINGNPMAUGUST 2026
Bastillion npm Package Vulnerability: Critical Authentication BypassEarly warning of a critical vulnerability in Bastillion npm package allowing unauthenticated access.
EARLY WARNINGNPMAUGUST 2026
SpiderFoot Vulnerability CVE-2026-75626: Critical Risk AlertEarly warning of a critical vulnerability in SpiderFoot that could allow API key theft.
EARLY WARNINGWORDPRESSAUGUST 2026
Forminator Forms Plugin Vulnerability: Critical Arbitrary File UploadForminator Forms plugin for WordPress has a critical vulnerability allowing remote code execution.
EARLY WARNINGNPMAUGUST 2026
Ray-Project Ray npm Package: Code Injection Vulnerability WarningEarly warning of a code injection vulnerability in Ray-Project Ray npm package. Assess your exposure now.
CONFIRMEDMACOSAUGUST 2026
Apple macOS Improper Authentication Vulnerability CVE-2026-65400 ConfirmedApple macOS contains an improper authentication vulnerability that could allow an attacker to authenticate to Screen Sharing without valid credentials.
EARLY WARNINGCISA_KEVAUGUST 2026
Broadcom VMware vCenter Path Traversal Vulnerability: Early WarningEarly warning of a high-severity path traversal vulnerability in Broadcom VMware vCenter.
EARLY WARNINGNPMAUGUST 2026
Microsoft SharePoint Weak Authentication Vulnerability: Early WarningEarly warning of a high-severity vulnerability in Microsoft SharePoint that allows unauthorized network access.
EARLY WARNINGNPMAUGUST 2026
MLflow npm Package Authorization Bypass: Early WarningEarly warning of an authorization bypass vulnerability in MLflow npm package versions below 3.15.0.
EARLY WARNINGNPMAUGUST 2026
Critical Vulnerability in MemOS npm Package: What You Need to KnowEarly warning of a critical vulnerability in the MemOS npm package that could allow unauthenticated remote access to admin API-key management.
EARLY WARNINGNPMAUGUST 2026
OpnForm npm Package Vulnerability: Critical CVE-2026-75106Early warning: OpnForm npm package vulnerability allows unauthenticated access to submission data.
EARLY WARNINGNPMAUGUST 2026
Critical Vulnerability in multicloud-operators-subscription Component ReportedEarly warning of a critical flaw in multicloud-operators-subscription that could allow privilege escalation.
EARLY WARNINGMAVENAUGUST 2026
Netty Maven Package Vulnerability: Memory Exhaustion RiskEarly warning of a critical vulnerability in Netty maven package versions, potentially leading to memory exhaustion.
EARLY WARNINGNPMAUGUST 2026
Etherpad Stored XSS Vulnerability: Early Warning and Mitigation StepsEarly warning of a stored XSS vulnerability in Etherpad's HTML export. Learn about the threat and mitigation steps.
EARLY WARNINGNPMAUGUST 2026
vm2 npm Package Vulnerability: Critical CVE Under InvestigationEarly warning of a critical vulnerability in the vm2 npm package that may allow host hijacking.
EARLY WARNINGNPMAUGUST 2026
vm2 npm Package Vulnerability: Critical CVE Under InvestigationEarly warning of a critical vulnerability in vm2 npm package that may enable sandbox escape to remote code execution.
EARLY WARNINGPYPIAUGUST 2026
Glances Package Vulnerability: Credential Leak in URL ValuesGlances package reportedly leaks credentials in URL values due to a function flaw.
EARLY WARNINGPYPIAUGUST 2026
Glances 4.5.5 Vulnerability: Incomplete Fix for CVE-2026-53925Glances 4.5.5 reportedly has an incomplete fix for CVE-2026-53925, allowing arbitrary file write and command chaining.
EARLY WARNINGPYPIAUGUST 2026
sqlparse Package Vulnerability: SQL Injection Risk via Unescaped BackslashesEarly warning: sqlparse package generates Python and PHP code from SQL input but fails to properly escape backslashes, allowing SQL injection.
EARLY WARNINGPYPIAUGUST 2026
sqlparse Package Vulnerability: SQL Injection Risk Through Unescaped BackslashesEarly warning about a vulnerability in sqlparse that allows SQL injection through unescaped backslashes.
EARLY WARNINGGOAUGUST 2026
Integer Overflow in new-api Go Package: Early WarningEarly warning of an integer overflow vulnerability in the new-api Go package leading to negative charges.
EARLY WARNINGGOAUGUST 2026
new-api Go Package Leaks Root Access Token: Early WarningEarly warning: new-api Go package reportedly leaks root access token. Upgrade to v1.0.0-rc.7 or later.
EARLY WARNINGGITHUB-ACTIONSAUGUST 2026
conflibot GitHub Action Vulnerability: Command Injection via Branch NamesEarly warning: conflibot GitHub Action is vulnerable to command injection. Upgrade to conflibot@v2.0.0 or v1.2.1.
EARLY WARNINGNPMAUGUST 2026
openssl_encrypt npm Package Vulnerability: Early WarningEarly warning of a critical vulnerability in openssl_encrypt npm package versions before 1.4.0.
EARLY WARNINGNPMAUGUST 2026
openssl_encrypt npm Package Vulnerability: Critical CVE-2026-74900Early warning of a critical vulnerability in openssl_encrypt npm package versions before 1.4.0.
EARLY WARNINGNPMAUGUST 2026
openssl_encrypt npm Package Vulnerability: Critical CVE-2026-74899Early warning of a critical vulnerability in openssl_encrypt npm package versions before 1.4.0.
EARLY WARNINGNPMAUGUST 2026
openssl_encrypt npm Package Vulnerability: Critical Risk AlertEarly warning of a critical vulnerability in openssl_encrypt npm package versions before 1.4.0.
EARLY WARNINGNPMAUGUST 2026
openssl_encrypt npm Package Vulnerability: Early WarningEarly warning of a critical vulnerability in openssl_encrypt npm package versions before 1.4.0.
EARLY WARNINGNPMAUGUST 2026
openssl_encrypt npm Package Vulnerability: Critical Rate Limiter FlawEarly warning of a critical vulnerability in openssl_encrypt npm package versions before 1.4.0.
CONFIRMEDNPMAUGUST 2026
openssl_encrypt npm Package Vulnerability: Critical Arbitrary Code Executionopenssl_encrypt npm package versions before 1.4.0 contain a critical vulnerability allowing arbitrary code execution.
EARLY WARNINGNPMAUGUST 2026
SiYuan <3.7.4 Vulnerability: Stored XSS RiskEarly warning of a critical stored XSS vulnerability in SiYuan <3.7.4. Upgrade to mitigate risk.
CONFIRMEDNPMAUGUST 2026
SiYuan < 3.7.4 Vulnerability: Critical In-Memory Secret ExposureSiYuan before 3.7.4 exposes in-memory secrets due to unauthenticated debug endpoints.
EARLY WARNINGNPMAUGUST 2026
Scriban npm Package Vulnerability: Access-Modifier Bypass ThreatScriban before 7.2.2 contains a critical vulnerability allowing CLR object property modification.
EARLY WARNINGNPMAUGUST 2026
SiYuan Kernel <= 3.7.3 Vulnerability: Critical Authentication BypassEarly warning: SiYuan kernel versions before 3.7.4 contain a critical improper restriction of excessive authentication attempts vulnerability.
EARLY WARNINGWORDPRESSAUGUST 2026
ARForms WordPress Plugin Vulnerable to PHP Object InjectionEarly warning: ARForms WordPress plugin <=1.8.5 has a critical PHP Object Injection vulnerability.
EARLY WARNINGWORDPRESSAUGUST 2026
Solace Extra WordPress Plugin Vulnerability: Critical CVE-2026-18316Early warning of a critical vulnerability in Solace Extra WordPress plugin. Assess your exposure and take immediate action.
EARLY WARNINGWORDPRESSAUGUST 2026
Frontend Admin by DynamiApps WordPress Plugin Vulnerability AlertEarly warning of a critical vulnerability in the Frontend Admin by DynamiApps WordPress plugin. Upgrade now.
EARLY WARNINGWORDPRESSAUGUST 2026
ProSolution WP Client Plugin Vulnerability: Critical Arbitrary File DeletionEarly warning of a critical vulnerability in ProSolution WP Client plugin for WordPress.
EARLY WARNINGNPMAUGUST 2026
SiYuan Cross-Site Scripting Vulnerability: Early WarningEarly warning for a critical cross-site scripting vulnerability in SiYuan versions before v3.7.4.
EARLY WARNINGNPMAUGUST 2026
SiYuan before v3.7.4 Vulnerability: Critical Risk AlertEarly warning of a critical vulnerability in SiYuan before v3.7.4. Learn about the risk and recommended actions.
EARLY WARNINGNPMAUGUST 2026
SiYuan < v3.7.4: Stored XSS Vulnerability AlertEarly warning of a critical stored XSS vulnerability in SiYuan versions before v3.7.4.
EARLY WARNINGNPMAUGUST 2026
SiYuan v3.7.4 Critical Vulnerability: Stored XSS in Style AttributesSiYuan versions before v3.7.4 have a critical vulnerability allowing stored XSS attacks.
EARLY WARNINGNPMAUGUST 2026
SiYuan < v3.7.4 Vulnerability: Critical Risk of Script ExecutionEarly warning of a critical vulnerability in SiYuan before v3.7.4, allowing script execution via HTML interpolation.
CONFIRMEDNPMAUGUST 2026
SiYuan < v3.7.4 Critical Vulnerability: Script Injection RiskSiYuan versions before v3.7.4 contain critical script injection vulnerabilities. Upgrade now.
EARLY WARNINGWORDPRESSAUGUST 2026
Link Library WordPress Plugin Vulnerability: Critical Arbitrary File DeletionEarly warning of a critical vulnerability in the Link Library WordPress plugin. Versions <= 7.9.4 are reportedly affected.
EARLY WARNINGWORDPRESSAUGUST 2026
WordPress Pods Plugin <= 3.3.9 Vulnerable to Privilege EscalationEarly warning: WordPress Pods plugin <= 3.3.9 vulnerable to Privilege Escalation via Authorization Bypass.
EARLY WARNINGWORDPRESSAUGUST 2026
TrueBooker WordPress Plugin Vulnerable to Account TakeoverEarly warning of a critical vulnerability in TrueBooker WordPress plugin. Versions up to 1.2.6 are reportedly affected.
EARLY WARNINGWORDPRESSAUGUST 2026
User Profile Builder WordPress Plugin Vulnerable to Authentication BypassUser Profile Builder WordPress plugin versions <=3.16.4 are vulnerable to Authentication Bypass.
EARLY WARNINGWORDPRESSAUGUST 2026
User Session Synchronizer WordPress Plugin Vulnerable to Authentication BypassEarly warning of a critical vulnerability in User Session Synchronizer WordPress plugin versions <=1.4.0.
EARLY WARNINGWORDPRESSAUGUST 2026
RapiSafe WordPress Plugin Vulnerability: Critical CVE-2026-14484Early warning of a critical vulnerability in RapiSafe WordPress plugin. Versions up to 1.0.4 are reportedly affected.
EARLY WARNINGCARGOAUGUST 2026
s2n-quic Rust Implementation Vulnerable to Excessive Memory AllocationEarly warning of a vulnerability in s2n-quic allowing denial of service via crafted CRYPTO frames.
EARLY WARNINGCARGOAUGUST 2026
s2n-quic Vulnerability: Excessive Memory Allocation WarningEarly warning of a vulnerability in s2n-quic that may lead to denial of service via excessive memory allocation.
EARLY WARNINGCARGOAUGUST 2026
SurrealDB Permissions Leak: Early Warning and Mitigation StepsEarly warning for SurrealDB permissions leak. Learn about the vulnerability and mitigation steps.
EARLY WARNINGCARGOAUGUST 2026
SurrealDB Permissions Leak: Potential Data Exposure RiskSurrealDB has a reported permissions leak that may expose array elements to unauthorized users.
EARLY WARNINGGITHUB-ACTIONSAUGUST 2026
Lima VM Vulnerability: Arbitrary User Could Gain Root PrivilegeEarly warning: Lima VM versions <=2.1.2 may allow an arbitrary user to gain root privileges.
EARLY WARNINGGITHUB-ACTIONSAUGUST 2026
Lima VM Guest Agent Socket Vulnerability: Early WarningEarly warning of a vulnerability in Lima VM that could allow arbitrary users to gain root privilege.
EARLY WARNINGGOAUGUST 2026
Authorizer Go Package: Zero-click Account Takeover VulnerabilityEarly warning of a high-severity vulnerability in the authorizer Go package that may allow zero-click account takeover.
EARLY WARNINGGOAUGUST 2026
SiYuan WebSocket Vulnerability: Unfiltered Edits Exposure RiskEarly warning: SiYuan versions before v3.7.4 may expose unfiltered edits to anonymous readers.
CONFIRMEDNPMAUGUST 2026
Grav API Plugin <= 1.0.12 Vulnerable to Remote Code ExecutionCritical vulnerability in Grav API plugin allows remote code execution. Upgrade to version 1.0.13 or later.
EARLY WARNINGGITHUB-ACTIONSAUGUST 2026
Grav API Plugin Vulnerability CVE-2026-72829Early warning of a critical vulnerability in Grav API plugin versions before 1.0.13. Upgrade to 1.0.13 or later.
CONFIRMEDPACKAGISTAUGUST 2026
getgrav/grav-plugin-api <= 1.0.12 Vulnerable to Account TakeoverCritical vulnerability in getgrav/grav-plugin-api <= 1.0.12 allows account takeover. Upgrade to version 1.0.13 or later.
EARLY WARNINGWORDPRESSAUGUST 2026
Wishlist Member WordPress Plugin Vulnerable to Account TakeoverCritical vulnerability in Wishlist Member WordPress plugin allows account takeover. Upgrade now.
EARLY WARNINGNPMAUGUST 2026
Budibase Vulnerability: Critical CVE-2026-72850 and CVE-2026-72851Early warning of critical vulnerabilities in Budibase versions before 3.40.0. Upgrade now.
EARLY WARNINGNPMAUGUST 2026
luci-app-openvpn npm Package Vulnerability: Critical CVE-2026-72841Early warning of a critical vulnerability in luci-app-openvpn npm package. Learn about the risk and recommended actions.
EARLY WARNINGNPMAUGUST 2026
Critical Vulnerability in filebrowser npm Package: What You Need to KnowEarly warning of a critical vulnerability in filebrowser npm package. Learn how to assess your exposure and mitigate the risk.
EARLY WARNINGNPMAUGUST 2026
IBM Langflow OSS Vulnerability: Critical CVE Under InvestigationEarly warning of a critical vulnerability in IBM Langflow OSS versions 1.0.0 through 1.9.6. Upgrade now.
EARLY WARNINGNPMAUGUST 2026
IBM Documentation Offline Vulnerability: Critical Arbitrary Code ExecutionEarly warning of a critical vulnerability in IBM Documentation Offline 1.0.0 through 1.4.1. Upgrade or apply a patch if available.
EARLY WARNINGNPMAUGUST 2026
CyberPanel JWT Secret Vulnerability: Critical Risk AlertCyberPanel before 3.0.0 has a critical JWT secret vulnerability. Upgrade to version 3.0.0 or later.
EARLY WARNINGPHPAUGUST 2026
Fluent Forms Pro 6.2.7 Vulnerability: Supply-Chain Attack AlertEarly warning of a critical vulnerability in Fluent Forms Pro 6.2.7. Check for compromise and upgrade immediately.
EARLY WARNINGNPMAUGUST 2026
Adobe Commerce Vulnerability CVE-2026-71362 Under Attack: Early WarningEarly warning of exploitation attempts targeting Adobe Commerce vulnerability CVE-2026-71362 shortly after patch release.
EARLY WARNINGGOAUGUST 2026
Argo Workflows CVE-2026-31892: Incomplete Fix DetectedEarly warning of an incomplete fix for CVE-2026-31892 in Argo Workflows. Monitor for updates and consider restricting templateReferencing.
EARLY WARNINGNPMAUGUST 2026
ep_etherpad-lite npm Package Vulnerability: What We KnowEarly warning of a vulnerability in ep_etherpad-lite npm package. Assess your exposure and take recommended actions.
EARLY WARNINGGOAUGUST 2026
SiYuan Vulnerability: Unauthorized Access to Sensitive ContentEarly warning of a vulnerability in SiYuan versions before v3.7.4 that may allow unauthorized access to sensitive content.
EARLY WARNINGGOAUGUST 2026
Siyuan <= 0.0.0-20260313024916-fd6526133bb3 Vulnerability: Early WarningEarly warning of a vulnerability in siyuan <= 0.0.0-20260313024916-fd6526133bb3. Upgrade to v3.7.4 or later.
EARLY WARNINGGOAUGUST 2026
SiYuan <= 0.0.0-20260313024916-fd6526133bb3 Vulnerability: Early WarningEarly warning: SiYuan versions before v3.7.4 may leak sensitive document content.
EARLY WARNINGNPMAUGUST 2026
Adobe Commerce CVE-2026-71362 Vulnerability: Early WarningEarly warning of attempts to exploit CVE-2026-71362 in Adobe Commerce and Magento e-commerce platforms.
EARLY WARNINGNPMAUGUST 2026
cluster-curator-controller Privilege Escalation Vulnerability: Early WarningEarly warning of a critical privilege escalation vulnerability in cluster-curator-controller. Assess your exposure now.
EARLY WARNINGNUGETAUGUST 2026
SIPSorcery NuGet Package Vulnerable to Denial of Service AttackSIPSorcery NuGet package <= 10.0.13 is under investigation for a Denial of Service vulnerability.
EARLY WARNINGNUGETAUGUST 2026
ssh.net NuGet Package Vulnerability: Arbitrary File Write RiskEarly warning of a high-severity vulnerability in ssh.net NuGet package allowing arbitrary file write.
EARLY WARNINGNUGETAUGUST 2026
ssh.net NuGet Package Vulnerability: Critical CVE WarningEarly warning of a critical vulnerability in ssh.net NuGet package. Assess your exposure now.
EARLY WARNINGCARGOAUGUST 2026
nimiq-blockchain Package Vulnerability: Validity Store Off-by-One ErrorEarly warning of a high severity vulnerability in nimiq-blockchain package. Upgrade recommended.
EARLY WARNINGCARGOAUGUST 2026
nimiq-blockchain Package Vulnerability: Validity Store Off-by-One ErrorEarly warning of a high-severity vulnerability in nimiq-blockchain package. Upgrade to patched version once released.
EARLY WARNINGNPMAUGUST 2026
Critical Flaw in Red Hat Advanced Cluster Management ComponentEarly warning of a critical vulnerability in multicloud-integrations, a component of Red Hat Advanced Cluster Management.
EARLY WARNINGCAUGUST 2026
libgit2 Shell Command Injection Vulnerability: Critical CVE-2026-5917Early warning of a critical vulnerability in libgit2 versions v0.27.0 through v1.9.0. Learn about the risk and recommended actions.
EARLY WARNINGPYPIAUGUST 2026
DB-GPT Package Vulnerable to Critical Path Traversal AttackDB-GPT package versions from v0.0.1 to v0.8.1 contain a critical unauthenticated path traversal vulnerability.
EARLY WARNINGNPMAUGUST 2026
PapersGPT for Zotero 0.6.1 Vulnerability: Critical Remote Code ExecutionEarly warning of a critical remote code execution vulnerability in PapersGPT for Zotero 0.6.1.
EARLY WARNINGNUGETAUGUST 2026
Out-of-bounds write vulnerability in.NET: CVE-2026-62871Early warning on a critical out-of-bounds write vulnerability in.NET affecting Microsoft.WindowsDesktop.App.Runtime package.
EARLY WARNINGNUGETAUGUST 2026
Microsoft.NET Vulnerability CVE-2026-62897: What You Need to KnowEarly warning about a critical vulnerability in Microsoft.NET projects using affected versions of Microsoft.WindowsDesktop.App.Runtime.
EARLY WARNINGNUGETAUGUST 2026
Integer Overflow in.NET Microsoft.WindowsDesktop.App.RuntimeEarly warning: Integer overflow vulnerability in.NET Microsoft.WindowsDesktop.App.Runtime package.
EARLY WARNINGNUGETAUGUST 2026
Out-of-bounds write in.NET: Microsoft.WindowsDesktop.App.RuntimeEarly warning of a critical vulnerability in Microsoft.WindowsDesktop.App.Runtime.nuget package.
EARLY WARNINGNUGETAUGUST 2026
Out-of-Bounds Write in.NET: Assess Your Exposure NowEarly warning of a critical vulnerability in.NET allowing local code execution. Check your.NET projects for affected versions.
EARLY WARNINGNUGETAUGUST 2026
.NET Elevation of Privilege Vulnerability (CVE-2026-62886)An integer overflow in.NET may allow unauthorized privilege elevation. Upgrade to patched versions.
EARLY WARNINGNUGETAUGUST 2026
Elevation of Privilege Vulnerability in.NET: Early WarningEarly warning of a high-severity elevation of privilege vulnerability in.NET packages.
EARLY WARNINGNUGETAUGUST 2026
Microsoft.NET Denial of Service Vulnerability: CVE-2026-62901Early warning for a.NET vulnerability allowing denial of service attacks. Check your.NET versions.
EARLY WARNINGNUGETAUGUST 2026
.NET Denial of Service Vulnerability: Assess Your Exposure NowEarly warning of a.NET vulnerability allowing denial of service attacks. Check your versions.
EARLY WARNINGNUGETAUGUST 2026
Microsoft QUIC Vulnerability: Critical CVE in nuget PackageEarly warning of a critical CVE in Microsoft QUIC affecting nuget package Microsoft.Native.Quic.MsQuic.OpenSSL.
EARLY WARNINGNUGETAUGUST 2026
Microsoft.NETCore.App.Runtime Vulnerability: Information Disclosure ThreatEarly warning of a high-severity vulnerability in Microsoft.NETCore.App.Runtime that could lead to information disclosure.
EARLY WARNINGNUGETAUGUST 2026
Microsoft.NET Information Disclosure Vulnerability: CVE-2026-62898Early warning: Microsoft.NET runtime vulnerability CVE-2026-62898 may allow information disclosure.
EARLY WARNINGNPMAUGUST 2026
Adobe Commerce Incorrect Authorization Vulnerability: Early WarningEarly warning of a critical vulnerability in Adobe Commerce that could lead to privilege escalation.
EARLY WARNINGNPMAUGUST 2026
cve-2026-71384 npm Package Vulnerability: Early WarningEarly warning of a critical vulnerability in the cve-2026-71384 npm package. Learn what is known and how to assess your exposure.
EARLY WARNINGGOAUGUST 2026
SeaweedFS SSRF Vulnerability: Critical Update for Versions Before 4.24Early warning for SeaweedFS SSRF vulnerability. Upgrade to version 4.24 or later.
EARLY WARNINGPACKAGISTAUGUST 2026
Craft CMS Authorization Bypass Vulnerability: Early WarningEarly warning of an authorization bypass vulnerability in Craft CMS versions 5.0.0-RC1 through 5.10.5.
EARLY WARNINGNPMAUGUST 2026
AVideo Unauthenticated File Write Vulnerability: Early WarningEarly warning of a critical vulnerability in AVideo that allows arbitrary file write. Assess your exposure and take action.
EARLY WARNINGNPMAUGUST 2026
Picketlink Federation SAML Vulnerability: Early Warning IssuedEarly warning issued for a critical flaw in Picketlink Federation SAML that could allow unauthenticated access.
CONFIRMEDCAUGUST 2026
CVE-2026-68820: Microsoft Windows Driver Zero-Day Under AttackMicrosoft Windows Ancillary Function Driver for WinSock contains a use-after-free vulnerability that allows local privilege escalation.
CONFIRMEDCISA_KEVAUGUST 2026
CVE-2026-20349: Cisco ASA and FTD Vulnerability ExploitedCisco ASA and FTD vulnerability CVE-2026-20349 exploited in the wild. Learn about the threat and recommended actions.
EARLY WARNINGPYPIAUGUST 2026
Feast Package Vulnerability: Critical CVE-2026-18948 AlertEarly warning of a critical vulnerability in Feast package. Learn about the flaw and how to assess your exposure.
EARLY WARNINGNPMAUGUST 2026
MaaS API Vulnerability CVE-2026-14450: Early WarningEarly warning for a critical vulnerability in MaaS API, CVE-2026-14450. Learn what is known and how to assess your exposure.
EARLY WARNINGPHPAUGUST 2026
SPIP Code Injection Vulnerability: Critical CVE-2026-66738 AlertEarly warning: SPIP versions before 4.4.18 contain a critical code injection vulnerability. Upgrade to 4.4.18 or later.
EARLY WARNINGNPMAUGUST 2026
ReadyEcommerce <= 4.5.1 SQL Injection Vulnerability: Early WarningEarly warning of a critical SQL injection vulnerability in ReadyEcommerce <= 4.5.1. Upgrade to 4.5.2 or later.
EARLY WARNINGMAVENAUGUST 2026
Apache Ranger Command Injection Vulnerability: Early WarningEarly warning of a critical command injection vulnerability in Apache Ranger versions 0.6 through 2.8.
CONFIRMEDNPMAUGUST 2026
Metabase npm Package SQL Injection Vulnerability ExploitedCritical SQL injection vulnerability in Metabase npm package exploited in the wild. Upgrade now.
EARLY WARNINGWORDPRESSAUGUST 2026
AI Copilot WordPress Plugin Vulnerable to Authorization BypassEarly reports indicate a critical vulnerability in the AI Copilot WordPress plugin.
CONFIRMEDGEMAUGUST 2026
Ruby JSON Gem Vulnerability: Critical Heap-Use-After-Free IssueRuby JSON gem versions from 0.4.0 to 2.19.1 contain a critical vulnerability leading to heap-use-after-free. Upgrade to a patched version.
EARLY WARNINGGEMAUGUST 2026
Ruby JSON Gem Vulnerability: Critical CVE Under InvestigationRuby JSON gem versions from 0.4.0 to 2.21.2 may have a critical vulnerability leading to crashes.
EARLY WARNINGPACKAGISTAUGUST 2026
CodeIgniter Framework File Upload Validation Bypass Under InvestigationEarly warning: CodeIgniter framework reportedly has a file upload validation vulnerability leading to potential remote code execution.
EARLY WARNINGPACKAGISTAUGUST 2026
CodeIgniter Query Builder SQL Injection Vulnerability Under InvestigationEarly warning: SQL injection vulnerability in CodeIgniter Query Builder's deleteBatch() method is under investigation.
EARLY WARNINGPYPIAUGUST 2026
GitPython Vulnerability: Arbitrary File Overwrites ReportedGitPython package vulnerability allows arbitrary file overwrites. Assess your exposure.
EARLY WARNINGPYPIAUGUST 2026
GitPython Package Vulnerability: Arbitrary File OverwritesGitPython package vulnerability allows arbitrary file overwrites due to unguarded git read-tree option forwarding.
EARLY WARNINGPACKAGISTAUGUST 2026
Craft CMS Passkey Login Vulnerability: Replayed WebAuthn AssertionsEarly warning: Craft CMS passkey login may accept replayed WebAuthn assertions. Assess your exposure now.
EARLY WARNINGNPMAUGUST 2026
ChainDrop npm Package Compromised by Worm: Early WarningEarly warning: ChainDrop npm package reportedly compromised by a worm spreading malicious code. Avoid use and monitor environments.
EARLY WARNINGWORDPRESSAUGUST 2026
TrueBooker WordPress Plugin Vulnerable to Authorization BypassEarly warning: TrueBooker plugin <=1.2.3 may allow password changes by unauthenticated users.
EARLY WARNINGWORDPRESSAUGUST 2026
TrueBooker WordPress Plugin Vulnerable to Account Takeover: Early WarningEarly warning: TrueBooker WordPress plugin <=1.2.3 reportedly vulnerable to critical account takeover via improper password reset validation.
CONFIRMEDNPMAUGUST 2026
Progress LoadMaster Command Injection Vulnerability: CVE-2026-8037Critical command injection flaw in Progress LoadMaster actively exploited. Upgrade now.
EARLY WARNINGNPMAUGUST 2026
Dinky npm Package Vulnerability: Critical Arbitrary File Write RiskEarly warning of a critical vulnerability in Dinky npm package <=1.2.5 allowing arbitrary file writes.
EARLY WARNINGNPMAUGUST 2026
Flowise <=3.1.4 Insecure Direct Object Reference VulnerabilityFlowise <=3.1.4 reportedly contains a critical vulnerability allowing credential access across workspaces.
EARLY WARNINGNPMAUGUST 2026
Ground Station <= 0.5.x: Critical Unauthenticated Database Destruction VulnerabilityEarly warning: Ground Station <= 0.5.x may allow unauthenticated database destruction and data injection.
EARLY WARNINGNPMAUGUST 2026
Mermaid npm Package Vulnerability: Prototype Pollution in Architecture DiagramsEarly warning of a high severity vulnerability in Mermaid npm package affecting versions 11.5.0 - 11.16.0.
EARLY WARNINGNPMAUGUST 2026
Mermaid npm Package Vulnerability: Prototype Pollution RiskEarly warning of a high severity vulnerability in Mermaid npm package due to prototype pollution.
EARLY WARNINGGOAUGUST 2026
Traefik Path Traversal Vulnerability: Authentication Bypass RiskEarly warning: Traefik's ReplacePathRegex middleware may allow authentication bypass.
EARLY WARNINGGITHUB-ACTIONSAUGUST 2026
Traefik Reverse Proxy Vulnerability Under Investigation: Early WarningTraefik's default reverse proxy may allow cross-user response poisoning. Upgrade to mitigate.
EARLY WARNINGGITHUB-ACTIONSAUGUST 2026
Traefik Reverse Proxy Vulnerability: Cross-User Response PoisoningEarly warning of a high-severity vulnerability in Traefik reverse proxy that could allow cross-user response poisoning.
EARLY WARNINGNPMAUGUST 2026
OpenChamber 1.11.7 Vulnerability: Critical Remote Code Execution RiskEarly warning of a critical unauthenticated remote code execution vulnerability in OpenChamber 1.11.7.
EARLY WARNINGNPMAUGUST 2026
TeamCity CVE-2026-63077 Under Active Exploitation: Critical WarningEarly warning: Critical vulnerability CVE-2026-63077 in JetBrains TeamCity is reportedly being exploited in the wild. Upgrade now.
EARLY WARNINGNPMAUGUST 2026
Nuxt DevTools Vulnerability: Arbitrary Command Execution RiskEarly warning of a critical vulnerability in Nuxt DevTools allowing unauthenticated RPC command execution.
EARLY WARNINGNPMAUGUST 2026
Nuxt DevTools npm Package Under Investigation for Arbitrary Command ExecutionEarly warning: Nuxt DevTools npm package reportedly allows arbitrary command execution on developer's host.
EARLY WARNINGNPMAUGUST 2026
Nuxt DevTools npm Package Vulnerability: Arbitrary Command ExecutionEarly warning of a critical vulnerability in Nuxt DevTools npm package allowing arbitrary command execution.
EARLY WARNINGNPMAUGUST 2026
Nuxt Server Islands Vulnerability: Unauthorized Component InstantiationEarly warning: Nuxt server islands may allow unauthorized component instantiation. Assess your exposure now.
EARLY WARNINGNPMAUGUST 2026
Nuxt Server Islands Vulnerability: Unauthorized Component InstantiationEarly warning of a high severity vulnerability in Nuxt server islands allowing unauthorized component instantiation.
EARLY WARNINGGOAUGUST 2026
rclone Archive Extract Command Vulnerability: Early WarningEarly warning of a high severity vulnerability in rclone archive extract command. Upgrade to version 1.74.3 or later.
EARLY WARNINGGOAUGUST 2026
rclone Package Vulnerability: PowerShell Injection Risk in SFTPEarly warning of a potential vulnerability in rclone allowing PowerShell injection via SFTP.
EARLY WARNINGGOAUGUST 2026
rclone Go Package Vulnerability: PowerShell Smart-Quote InjectionEarly warning: rclone Go package <= 1.74.4 may allow SFTP server-side command execution via PowerShell smart-quote injection.
EARLY WARNINGGOAUGUST 2026
rclone Infinite Scale TUS Creation Transport Error Under InvestigationEarly warning: rclone may crash due to transport failure during Infinite Scale TUS creation POST requests.
EARLY WARNINGGOAUGUST 2026
rclone <= 1.74.0: Nil-Response Panic in Infinite Scale TUS CreationEarly warning of a potential panic in rclone <= 1.74.0 due to a nil-response error during Infinite Scale TUS creation.
EARLY WARNINGNPMAUGUST 2026
Critical Vulnerability in boringproxy <= 0.10.0: Newline Injection ThreatEarly warning of a critical vulnerability in boringproxy <= 0.10.0 allowing newline injection into SSH authorized_keys.
EARLY WARNINGGOAUGUST 2026
rclone Package Path Validation Vulnerability: Early WarningEarly warning of a potential vulnerability in rclone package versions v1.40 through v1.74.4 due to incomplete path validation.
EARLY WARNINGGOAUGUST 2026
rclone Package Path Validation Issue: Early WarningEarly warning of a critical path validation issue in rclone package versions v1.40 through v1.74.4.
EARLY WARNINGNPMAUGUST 2026
electron: Security Threat DetailsThe Electron npm package has a vulnerability where the `mode` option of `webContents.openDevTools()` was not sanitized, allowing scripts under attacker con
EARLY WARNINGNPMAUGUST 2026
electron: Security Threat DetailsThe Electron npm package has a vulnerability where the `mode` option of `webContents.openDevTools()` was not sanitized, allowing scripts under attacker con
EARLY WARNINGKUBERNETESAUGUST 2026
Red Hat Advanced Cluster Management for Kubernetes Privilege Escalation ThreatEarly warning: A critical vulnerability in Red Hat Advanced Cluster Management for Kubernetes may allow privilege escalation.
EARLY WARNINGNPMAUGUST 2026
Critical Flaw in ClusterCurator for Kubernetes DetectedEarly warning: A critical vulnerability in ClusterCurator may allow privilege escalation.
EARLY WARNINGWORDPRESSAUGUST 2026
Multi Uploader for Gravity Forms Plugin Vulnerable to Unauthorized Media DeletionEarly warning: Multi Uploader for Gravity Forms plugin for WordPress may allow unauthorized media deletion.
EARLY WARNINGWORDPRESSAUGUST 2026
Easy Post Submission WordPress Plugin Vulnerability: Critical CVE-2026-4431Early warning: Easy Post Submission plugin <=2.3.0 for WordPress is reportedly vulnerable to unauthorized data modification.
EARLY WARNINGWORDPRESSAUGUST 2026
Kadence Memberships WordPress Plugin Vulnerable to Account TakeoverEarly warning: Kadence Memberships plugin for WordPress may allow account takeover via password reset link poisoning.
EARLY WARNINGCISA_KEVAUGUST 2026
JetBrains TeamCity Vulnerability Under Active ExploitationEarly warning: JetBrains TeamCity vulnerability CVE-2026-63077 is reportedly being exploited in the wild.
EARLY WARNINGPHPAUGUST 2026
MaxSite CMS PHP Object Injection Vulnerability Under InvestigationEarly warning: MaxSite CMS reportedly contains a critical PHP object injection vulnerability allowing remote code execution.
EARLY WARNINGNPMAUGUST 2026
Ghost Admin Universal Import Feature Vulnerable to XSSEarly warning: Ghost Admin's Universal Import feature may be vulnerable to XSS attacks.
EARLY WARNINGNPMAUGUST 2026
Ghost Admin Universal Import Vulnerability: Cross-Site Scripting RiskEarly warning of a potential XSS vulnerability in Ghost Admin Universal Import feature. Assess your exposure now.
EARLY WARNINGPYPIAUGUST 2026
Open WebUI Package Vulnerability: Authenticated Users Can Stall WorkersEarly warning: Open WebUI package allows authenticated users to stall workers via crafted knowledge-search patterns.
EARLY WARNINGPYPIAUGUST 2026
Open WebUI Package Vulnerability: Denial of Service ThreatEarly warning of a denial of service vulnerability in Open WebUI package versions prior to 0.11.0.
EARLY WARNINGPYPIAUGUST 2026
Open WebUI Package Discloses Tool Source Code to Read-Only UsersEarly warning: Open WebUI package may expose tool source code to authenticated non-admin users.
EARLY WARNINGPYPIAUGUST 2026
Open WebUI Python Package: Source Code Disclosure VulnerabilityEarly warning: Open WebUI package may expose source code to read-only users.
CONFIRMEDPHPAUGUST 2026
MaxSite CMS Remote Code Execution Vulnerability (CVE-2026-70553)MaxSite CMS contains a remote code execution vulnerability allowing unauthenticated attackers to inject arbitrary PHP code.
CONFIRMEDNPMAUGUST 2026
MaxSite CMS <= 109.5 Authentication Bypass & RCE VulnerabilitiesCritical vulnerabilities in MaxSite CMS <= 109.5 allow unauthenticated remote code execution and admin access.
EARLY WARNINGNPMAUGUST 2026
Open WebUI Vulnerability: Same-Origin XSS to Account TakeoverEarly warning: Open WebUI <0.11.0 may allow authenticated users to run arbitrary scripts, leading to account takeover.
EARLY WARNINGNPMAUGUST 2026
Open WebUI Vulnerability: Same-Origin XSS to Account TakeoverEarly warning of a high-severity vulnerability in Open WebUI that could lead to account takeover.
CONFIRMEDNPMAUGUST 2026
Flowise OAuth2 Token Refresh Endpoint Vulnerability: Critical ThreatFlowise package's unauthenticated OAuth2 token refresh endpoint poses a high severity threat, enabling unauthorized access to connected services.
EARLY WARNINGPHPAUGUST 2026
Atlas-Livre Improper Access Control Vulnerability Under InvestigationAtlas-Livre reportedly contains a critical improper access control vulnerability allowing unauthenticated attackers to bypass session-based authentication guards.
EARLY WARNINGNPMAUGUST 2026
Flowise npm Package Reportedly Compromised via Unicode Homoglyph BypassEarly warning: Flowise npm package may have been compromised, leading to potential remote code execution.
EARLY WARNINGNPMAUGUST 2026
OpenCode Studio <= 2.4.3 Missing Authentication Vulnerability Early WarningEarly warning: OpenCode Studio <= 2.4.3 reportedly allows unauthenticated remote file access and deletion.
EARLY WARNINGPYPIAUGUST 2026
kotaemon <=0.12.0 Vulnerable to Remote Code ExecutionEarly warning: kotaemon package through version 0.12.0 reportedly contains an insecure deserialization vulnerability.
EARLY WARNINGNPMAUGUST 2026
Flowise Sandbox Escape Vulnerability: Early Warning for EngineersEarly warning: Flowise sandbox escape vulnerability allows RCE as root. Upgrade and review custom NodeVM configurations.
EARLY WARNINGNPMAUGUST 2026
Flowise AI Remote Code Execution Vulnerability via TypeORM DataSourceEarly warning: Flowise AI version 3.1.2 reportedly has a remote code execution vulnerability through TypeORM DataSource.
CONFIRMEDNPMAUGUST 2026
Credential-Stealing npm Worm Spreads Through Keyv and Cacheable NamespacesHigh-severity supply-chain attack compromises hundreds of npm packages, stealing credentials.
CONFIRMEDNPMAUGUST 2026
npm Supply Chain Attack: Keyv, Cacheable Packages CompromisedConfirmed npm supply chain attack compromises keyv, cacheable packages. Check exposure now.
CONFIRMEDNPMAUGUST 2026
Keyv and Friends npm Packages Compromised in Supply Chain AttackKeyv and friends npm packages compromised. Malicious code harvesting credentials and spreading.
CONFIRMEDNPMAUGUST 2026
keyv and cacheable npm Packages Compromised in Supply Chain Attackkeyv and cacheable npm packages compromised. Assess your exposure and consider alternatives.
EARLY WARNINGNPMAUGUST 2026
N-able N-central npm Package Reportedly Exploited in the WildN-able N-central npm package has a high-severity flaw, CVE-2026-18577, under investigation for active exploitation.
CONFIRMEDNPMAUGUST 2026
N-able N-central Authentication Bypass: Critical Flaw ExploitedN-able N-central suffers from a critical authentication bypass flaw (CVE-2026-18556) actively exploited in the wild. Upgrade immediately.
CONFIRMEDNPMAUGUST 2026
Langflow Code Injection Vulnerability Actively ExploitedLangflow contains a critical code injection vulnerability (CVE-2026-9198) actively exploited in the wild.
EARLY WARNINGMAVENAUGUST 2026
Apache Tomcat Vulnerability Under Investigation: Sensitive Data Exposure RiskEarly warning: Apache Tomcat may have a vulnerability allowing sensitive data exposure. Investigate your exposure now.
EARLY WARNINGNPMAUGUST 2026
Sequelize v6.37.3 SQL Injection Vulnerability: Early WarningEarly warning: Sequelize v6.37.3 may be vulnerable to SQL injection when dialect is set to 'oracle'.
EARLY WARNINGPYPIAUGUST 2026
gitpython: Security Threat DetailsThe GitPython package allows arbitrary file read via Repo.archive() due to an incomplete denylist for unsafe options. This permits reading files from outsi
EARLY WARNINGPYPIAUGUST 2026
GitPython Vulnerability: Arbitrary File Overwrite and Read RiskEarly warning of a high severity vulnerability in GitPython allowing arbitrary file overwrite and read.
EARLY WARNINGPYPIAUGUST 2026
GitPython Vulnerability: Arbitrary File Overwrite and Read RiskEarly warning about a GitPython vulnerability that allows arbitrary file overwrite and read through unguarded git option forwarding.
EARLY WARNINGNPMAUGUST 2026
Potential Vulnerabilities in undici npm PackageUndici npm package under investigation for shared-cache disclosure and parse-time crash.
EARLY WARNINGNPMAUGUST 2026
undici npm Package Vulnerabilities Disclosedundici npm package has issues in its cache interceptor that may lead to information disclosure and crashes.
EARLY WARNINGNPMAUGUST 2026
Socket.IO Vulnerability: Potential Memory Exhaustion ThreatReportedly, a specially crafted Socket.IO packet can cause memory exhaustion. Assess your exposure now.
EARLY WARNINGNPMAUGUST 2026
Socket.IO Memory Exhaustion Vulnerability: Early WarningEarly warning of a memory exhaustion vulnerability in Socket.IO. Assess your exposure and upgrade to patched versions.
EARLY WARNINGPHPAUGUST 2026
OpenEMR <= 8.2.0: Remote Code Execution Vulnerability ReportedEarly warning: OpenEMR <= 8.2.0 may contain a critical remote code execution vulnerability.
EARLY WARNINGGITHUB-ACTIONSAUGUST 2026
SiYuan <= v3.7.2: SQL Injection via /api/search/searchEmbedBlockEarly warning: SiYuan <= v3.7.2 may expose SQL injection vulnerability. Upgrade to v3.7.3.
EARLY WARNINGGOAUGUST 2026
SiYuan SQL Injection Vulnerability: Critical CVE Under InvestigationEarly warning: SiYuan versions before v3.7.3 may have SQL injection vulnerabilities.
CONFIRMEDNPMAUGUST 2026
SiYuan SQL Injection Vulnerability: Critical Risk to Database IntegritySiYuan versions before 3.7.3 have a critical SQL injection vulnerability affecting database security.
EARLY WARNINGNPMAUGUST 2026
SiYuan <= v3.7.2 SQL Injection Vulnerability: Early WarningEarly warning: SiYuan <= v3.7.2 may expose critical SQL injection vulnerability. Upgrade to v3.7.3.
EARLY WARNINGNPMAUGUST 2026
SiYuan SQL Injection Vulnerability: Critical Risk for Versions < v3.7.3Early warning: SiYuan versions before v3.7.3 may have critical SQL injection vulnerability.
EARLY WARNINGPHPAUGUST 2026
Telenia Software TVox Authentication Bypass Vulnerability Under InvestigationEarly warning: Telenia Software TVox <=26.5.3 and <=24.9.21 may have critical authentication bypass vulnerability.
CONFIRMEDNPMAUGUST 2026
N-able npm Package Vulnerability CVE-2026-18577 Exploited in the WildN-able npm package vulnerability CVE-2026-18577 has been exploited. Monitor for signs of exploitation and ensure you are using the latest patched version.
CONFIRMEDNPMAUGUST 2026
N-able N-central Auth Bypass Exploited: What We KnowN-able N-central contains an authentication bypass vulnerability exploited in the wild. Upgrade to the latest version.
EARLY WARNINGPYPIAUGUST 2026
PyAthena SQL Injection Vulnerability: Early Warning IssuedEarly warning issued for PyAthena SQL injection vulnerability allowing data exfiltration and destructive statements.
EARLY WARNINGWORDPRESSAUGUST 2026
WooCommerce - Social Login WordPress Plugin Vulnerable to Authentication BypassEarly warning: WooCommerce - Social Login plugin <=2.8.7 for WordPress may allow unauthenticated logins.
EARLY WARNINGPYPIAUGUST 2026
GitPython 3.1.50 Vulnerability: Gate Bypass During CloneGitPython 3.1.50 reportedly allows unsafe option gate bypass during clone.
EARLY WARNINGNPMAUGUST 2026
Axios Prototype Pollution Vulnerability: Early WarningEarly warning: Axios versions >=1.15.2 and <1.18.0 may be vulnerable to prototype pollution in Basic auth handling.
EARLY WARNINGNPMAUGUST 2026
Axios Prototype Pollution Vulnerability: Early WarningEarly warning of a prototype pollution vulnerability in Axios versions >=1.15.2 and <1.18.0.
EARLY WARNINGNPMAUGUST 2026
ArcadeDB Vulnerability: Potential Arbitrary JavaScript Code ExecutionEarly warning: ArcadeDB versions before 26.7.2 may allow arbitrary JavaScript code execution.
CONFIRMEDNPMAUGUST 2026
ArcadeDB < 26.7.2: Critical Vulnerabilities Allow OS Command ExecutionArcadeDB versions before 26.7.2 have critical vulnerabilities allowing OS command execution.
EARLY WARNINGPYPIAUGUST 2026
GitPython 3.1.50 Vulnerability: Critical CVE-2026-67324 AlertEarly warning on GitPython 3.1.50 vulnerability CVE-2026-67324, potentially allowing command execution during clone.
EARLY WARNINGGITHUB-ACTIONSAUGUST 2026
Wazuh GitHub Actions Vulnerability: Shell Injection ThreatEarly warning of a critical shell injection vulnerability in Wazuh GitHub Actions workflows.
CONFIRMEDCAUGUST 2026
FreeRDP <= 3.28.0: Critical TLS and Buffer Overflow VulnerabilitiesFreeRDP <= 3.28.0 contains critical TLS certificate validation and buffer overflow vulnerabilities.
EARLY WARNINGWORDPRESSAUGUST 2026
Single Sign On For TNG WordPress Plugin Vulnerable to Authentication BypassEarly warning: Single Sign On For TNG WordPress plugin <=2.0.0 vulnerable to critical authentication bypass.
EARLY WARNINGWORDPRESSAUGUST 2026
FormGent WordPress Plugin Vulnerability: Unauthorized File Deletion RiskEarly warning of a critical vulnerability in FormGent WordPress plugin <=1.9.2, potentially allowing unauthorized file deletion.
EARLY WARNINGGEMJULY 2026
guard-livereload Ruby Gem Directory Traversal Vulnerability Under InvestigationEarly warning: guard-livereload gem has a directory traversal vulnerability allowing arbitrary file reading.
EARLY WARNINGGEMJULY 2026
guard-livereload Ruby Gem Directory Traversal Vulnerability Under InvestigationEarly warning: guard-livereload gem has a reported directory traversal issue allowing remote file reading.
EARLY WARNINGPYPIJULY 2026
ComfyUI v0.23.0 Unsafe Deserialization Vulnerability Under InvestigationEarly warning: ComfyUI v0.23.0 may contain a critical deserialization vulnerability allowing remote code execution.
EARLY WARNINGNPMJULY 2026
@apostrophecms/file npm Package Vulnerability: Early WarningEarly warning of a potential SSRF vulnerability in @apostrophecms/file npm package affecting versions <= 4.30.0.
EARLY WARNINGNPMJULY 2026
Apostrophe npm Package Under Investigation for Prototype PollutionEarly warning: Apostrophe npm package may have prototype pollution vulnerability leading to authorization bypass.
EARLY WARNINGPYPIJULY 2026
sentence-transformers Package Vulnerability: Critical Security BypassEarly warning: sentence-transformers package reportedly contains a critical security bypass vulnerability.
EARLY WARNINGCARGOJULY 2026
zaino-state Rust Crate Vulnerability: Infinite Loop RiskEarly warning: zaino-state crate has unbounded async function that may cause infinite loops and high CPU usage.
EARLY WARNINGCARGOJULY 2026
zaino-state Rust Crate Vulnerability: Recursive Async Function RiskEarly warning: zaino-state Rust crate has a recursive, unbounded async function that may cause infinite loops.
EARLY WARNINGNUGETJULY 2026
ImageMagick XCF Decoder Vulnerability: Integer Overflow RiskEarly warning: ImageMagick XCF decoder may have an integer overflow vulnerability leading to potential crashes.
EARLY WARNINGNUGETJULY 2026
ImageMagick XCF Decoder Vulnerability: Potential Integer OverflowEarly warning of a potential integer overflow vulnerability in ImageMagick's XCF decoder.
EARLY WARNINGGEMJULY 2026
Savon::Model Gem Vulnerability: Potential Ruby Code InjectionEarly warning: Savon::Model gem may allow Ruby code injection via WSDL operation names. Upgrade to Savon 2.17.2 or later.
EARLY WARNINGGEMJULY 2026
Savon::Model Gem Vulnerability: Ruby Code Injection RiskEarly warning: Savon::Model gem reportedly allows Ruby code injection via WSDL operation names.
EARLY WARNINGNPMJULY 2026
Jodit npm Package Under Investigation for Potential XSS VulnerabilityJodit npm package is reportedly vulnerable to XSS via SVG nested script, under investigation.
EARLY WARNINGGOJULY 2026
vault-secrets-webhook Vulnerability: Unauthorized Outbound Connections RiskEarly warning on vault-secrets-webhook vulnerability allowing unauthorized outbound connections and potential token theft.
EARLY WARNINGGOJULY 2026
Capsule Package Vulnerability: Regex Panic on Node Admission RequestsEarly warning of a potential vulnerability in the Capsule package that may cause cluster-wide denial of service.
EARLY WARNINGPYPIJULY 2026
OnionShare 2.6.3 Vulnerability: Symlink Following RiskEarly warning: OnionShare 2.6.3 reportedly follows symlinks in shared directories, potentially exposing local files.
EARLY WARNINGGOJULY 2026
Wings Package Vulnerability: Sensitive Information Exposure RiskEarly warning: Wings package reportedly exposes sensitive node configuration secrets.
EARLY WARNINGWORDPRESSJULY 2026
Realtyna Organic IDX and WPL Real Estate Plugins Under Investigation for Critical VulnerabilityEarly warning: Realtyna Organic IDX and WPL Real Estate plugins for WordPress may have a critical file upload vulnerability.
EARLY WARNINGNPMJULY 2026
OpenClaw Dashboard v3.0.0 Stored XSS Vulnerability: Early WarningEarly warning of a critical stored XSS vulnerability in OpenClaw Dashboard v3.0.0. Administrators may be at risk.
EARLY WARNINGNPMJULY 2026
AWS Amplify Studio Package Input Validation Issue: Early WarningAWS Amplify Studio package <=2.20.2 has an input validation issue allowing arbitrary JavaScript execution.
EARLY WARNINGNPMJULY 2026
Spikster npm Package Vulnerability: Critical Missing Authentication IssueEarly warning of a critical vulnerability in Spikster npm package allowing unauthenticated access to API routes.
EARLY WARNINGNPMJULY 2026
juggle npm Package Under Investigation for Remote Code Execution VulnerabilityEarly warning: juggle npm package version 1.6.0 may contain a critical RCE vulnerability.
CONFIRMEDNPMJULY 2026
Critical Vulnerability in IBM Langflow OSS: Remote Code Execution RiskIBM Langflow OSS versions 1.0.0 through 1.10.0 are vulnerable to remote code execution due to improper input validation.
EARLY WARNINGGEMJULY 2026
Active Storage in Rails: Possible Arbitrary File Read and RCEEarly warning: Active Storage in Rails applications may allow unauthenticated attackers to read arbitrary files and potentially execute remote code.
EARLY WARNINGNPMJULY 2026
IBM Langflow OSS Vulnerability: Critical Remote Code Execution RiskEarly warning of a critical vulnerability in IBM Langflow OSS versions 1.0.0 through 1.10.1, potentially allowing unauthenticated remote code execution.
EARLY WARNINGGEMJULY 2026
MessagePack Ruby Gem Vulnerability: Use-After-Free in Buffer#clearEarly warning of a high-severity vulnerability in the MessagePack Ruby gem that may lead to cross-buffer information disclosure.
EARLY WARNINGNPMJULY 2026
UMAI Vision Traffic Analysis System SQL Injection Vulnerability ReportedEarly warning: UMAI Vision Traffic Analysis System versions 30 before 34 may be vulnerable to SQL injection.
EARLY WARNINGNPMJULY 2026
SolarWinds Web Help Desk SAML Bypass Vulnerability Under InvestigationSolarWinds Web Help Desk is reportedly affected by a critical SAML authentication bypass vulnerability.
EARLY WARNINGPYPIJULY 2026
linuxfabrik-lib Package Vulnerability: Potential Credential ExposureEarly warning on linuxfabrik-lib package vulnerability that may expose credentials. Upgrade to version 6.0.0 or later.
EARLY WARNINGPYPIJULY 2026
linuxfabrik-lib Package Vulnerability: Potential Credential ExposureEarly warning: linuxfabrik-lib <6.0.0 may forward credential headers across cross-origin redirects, potentially exposing sensitive tokens.
EARLY WARNINGGEMJULY 2026
MCP Ruby SDK: Potential DoS via Unbounded JSON-RPC RequestEarly warning: MCP Ruby SDK may be vulnerable to DoS attacks due to unbounded JSON-RPC request handling.
EARLY WARNINGGEMJULY 2026
MCP Ruby SDK Vulnerability: Potential Memory Allocation AttackEarly warning: MCP Ruby SDK may be vulnerable to uncontrolled memory allocation via oversized JSON-RPC requests.
EARLY WARNINGGEMJULY 2026
MCP Ruby SDK: Potential Memory Exhaustion via Unbounded Session RetentionEarly warning: MCP Ruby SDK's StreamableHTTPTransport may allow memory exhaustion due to unbounded session retention.
EARLY WARNINGGEMJULY 2026
MCP Ruby SDK: Potential Memory Exhaustion via Session FloodEarly warning: MCP Ruby SDK's StreamableHTTPTransport may allow memory exhaustion through unbounded session retention.
EARLY WARNINGGEMJULY 2026
MCP Ruby SDK Vulnerability: Memory Exhaustion RiskEarly warning of a potential memory exhaustion vulnerability in MCP Ruby SDK.
EARLY WARNINGGEMJULY 2026
MCP Ruby SDK Vulnerability: Memory Exhaustion Risk ReportedEarly warning: MCP Ruby SDK may be vulnerable to memory exhaustion due to unbounded line buffer in stdio transports.
CONFIRMEDGEMJULY 2026
MCP Gem DNS-Rebinding Flaw Exposes Data to Cross-Origin AttacksConfirmed: MCP gem's Streamable HTTP transport lacks DNS-rebinding protection, enabling cross-origin attacks.
EARLY WARNINGGEMJULY 2026
MCP Ruby SDK Vulnerability: DNS-Rebinding Protection MissingEarly warning: MCP Ruby SDK's Streamable HTTP transport may lack DNS-rebinding protection, enabling cross-origin attacks.
EARLY WARNINGNPMJULY 2026
CentreStack Cryptographic Key Vulnerability: Early WarningCentreStack before 17.5 reportedly contains a hardcoded cryptographic key vulnerability allowing unauthenticated remote code execution.
EARLY WARNINGNPMJULY 2026
npm Packages debug and chalk Reportedly Hijacked by North KoreaAmazon links the npm packages debug and chalk to North Korean hackers, with crypto theft reported.
EARLY WARNINGWORDPRESSJULY 2026
ASE Pro WordPress Plugin Vulnerable to Remote Code ExecutionEarly warning: ASE Pro plugin for WordPress may be vulnerable to RCE due to insufficient nonce validation.
EARLY WARNINGGEMJULY 2026
Possible Path Traversal in Active Record Tenanted GemEarly warning: Active Record Tenanted gem may allow arbitrary file access via path traversal.
EARLY WARNINGGOJULY 2026
Fluentd Configuration Injection in Logging Operator Under InvestigationEarly warning: Fluentd configuration injection in Logging operator may allow remote code execution.
EARLY WARNINGGOJULY 2026
prebid-server Package Vulnerability: Request Forgery ThreatEarly warning: prebid-server package reportedly has a request forgery vulnerability allowing possible data extraction.
EARLY WARNINGGITHUB-ACTIONSJULY 2026
prebid-server GitHub Action Vulnerability: Potential Data Extraction RiskEarly warning: prebid-server GitHub Action may be vulnerable to request forgery, risking data extraction from the host environment.
EARLY WARNINGNPMJULY 2026
nanoid npm Package Under Investigation for Infinite Loop VulnerabilityEarly warning: nanoid npm package versions before 5.1.6 may contain an infinite loop vulnerability leading to denial-of-service.
EARLY WARNINGMAVENJULY 2026
veraPDF Validation XXE Vulnerability: Early WarningEarly warning of a potential XXE vulnerability in veraPDF-validation allowing file reading and SSRF.
EARLY WARNINGMAVENJULY 2026
veraPDF Validation XXE Vulnerability: Early WarningEarly warning: veraPDF Validation XXE vulnerability may allow file reading and SSRF.
EARLY WARNINGMAVENJULY 2026
veraPDF-validation XXE Vulnerability: Early WarningEarly warning of an XML External Entity Injection vulnerability in veraPDF-validation.
EARLY WARNINGNPMJULY 2026
swagger-typescript-api npm Package Code Injection VulnerabilityEarly warning: swagger-typescript-api npm package reportedly vulnerable to code injection via unescaped URL.
EARLY WARNINGNPMJULY 2026
swagger-typescript-api npm Package Under Investigation for Code InjectionEarly warning: swagger-typescript-api may be vulnerable to code injection via unescaped URL.
EARLY WARNINGWORDPRESSJULY 2026
Cost Calculator Builder PRO WordPress Plugin Vulnerable to RCEEarly warning: Cost Calculator Builder PRO plugin for WordPress is reportedly vulnerable to Remote Code Execution.
EARLY WARNINGWORDPRESSJULY 2026
Meta Box AIO WordPress Plugin Vulnerability: Critical CVE-2026-14488Early warning: Meta Box AIO WordPress plugin <=3.8.0 vulnerable to unauthorized deletion of posts and pages.
EARLY WARNINGWORDPRESSJULY 2026
Spreadsheet Price Changer for WordPress Vulnerable to Admin Account CreationEarly warning: Spreadsheet Price Changer for WordPress plugin has a critical vulnerability allowing unauthenticated admin account creation.
EARLY WARNINGWORDPRESSJULY 2026
Advanced Responsive Video Embedder WordPress Plugin Under InvestigationEarly warning: Advanced Responsive Video Embedder plugin for WordPress is reportedly vulnerable to Authentication Bypass.
CONFIRMEDCISA_KEVJULY 2026
Cisco Secure FMC Zero-Day: Static Credentials Expose Sensitive DataCisco Secure Firewall Management Center (FMC) has a hard-coded password vulnerability actively exploited in the wild.
EARLY WARNINGGEMJULY 2026
Pagy Gem I18n Locale Option Vulnerability: Early WarningEarly warning: Pagy gem's I18n locale option may allow untrusted input to influence file paths.
EARLY WARNINGGEMJULY 2026
Pagy Gem I18n Locale Option Vulnerability: Early WarningEarly warning of a potential vulnerability in the Pagy gem's I18n locale option. Upgrade to version 43.5.6 or later.
EARLY WARNINGCARGOJULY 2026
skilo cargo Package Vulnerability: Arbitrary Local File DisclosureEarly warning of a vulnerability in skilo cargo package allowing arbitrary local file disclosure via symbolic links.
EARLY WARNINGCARGOJULY 2026
skilo Package Vulnerability: Symbolic Link Handling IssueEarly warning of a vulnerability in skilo package versions 0.5.0 to 0.11.0 due to improper symbolic link handling.
EARLY WARNINGNPMJULY 2026
@hypequery/clickhouse npm Package SQL Injection Vulnerability WarningEarly warning: @hypequery/clickhouse npm package has a SQL injection vulnerability. Upgrade to version 2.0.2 or later.
EARLY WARNINGGOJULY 2026
goshs Go Package: SFTP Authentication Bypass via Empty PasswordEarly warning: goshs Go package reportedly allows SFTP authentication bypass with empty password.
EARLY WARNINGPYPIJULY 2026
datamodel-code-generator Vulnerable to Code Injection via default_factoryEarly warning: datamodel-code-generator may be vulnerable to code injection through attacker-controlled default_factory schema field.
EARLY WARNINGPYPIJULY 2026
datamodel-code-generator Package Vulnerable to Code InjectionEarly warning: datamodel-code-generator package may be vulnerable to code injection via attacker-controlled schema.
EARLY WARNINGPYPIJULY 2026
datamodel-code-generator Vulnerability: Schema-Driven Code ExecutionEarly warning: datamodel-code-generator package may allow arbitrary Python code execution via malicious input schemas.
EARLY WARNINGPYPIJULY 2026
datamodel-code-generator Vulnerable to Arbitrary Local File ReadEarly warning: datamodel-code-generator may allow arbitrary local file read via XSD schemaLocation path traversal.
EARLY WARNINGNUGETJULY 2026
Buffer Overflow in EncryptedXml Class:.NET Vulnerability Under InvestigationEarly warning: Buffer overflow vulnerability in EncryptedXml class of.NET may lead to Denial of Service attacks.
EARLY WARNINGNUGETJULY 2026
Buffer Overflow in.NET EncryptedXml Class: Denial of Service RiskEarly warning of a buffer overflow vulnerability in.NET EncryptedXml class, potentially leading to Denial of Service attacks.
EARLY WARNINGGOJULY 2026
Cosmos-Server Authentication Bypass via Header Smuggling Under InvestigationEarly warning: Cosmos-Server reportedly has an authentication bypass vulnerability through forward-auth header smuggling.
EARLY WARNINGGOJULY 2026
Cosmos-Server's Public-Devices Endpoint Discloses MetadataEarly warning: Cosmos-Server's public-devices endpoint may disclose device metadata due to accepting arbitrary bearer tokens.
EARLY WARNINGGOJULY 2026
Cosmos-Server Public-Devices Endpoint Vulnerability: Early WarningEarly warning: Cosmos-Server's public-devices endpoint may disclose device metadata with arbitrary bearer tokens.
EARLY WARNINGPYPIJULY 2026
pytonapi Webhook Custom Path Authentication Bypass VulnerabilityEarly warning: pytonapi package has a reported webhook custom path authentication bypass vulnerability.
EARLY WARNINGNPMJULY 2026
Joyfill npm Packages @joyfill/components and @joyfill/layouts Under InvestigationMalicious beta versions of Joyfill npm packages reportedly contain a remote access trojan and credential stealer.
EARLY WARNINGPACKAGISTJULY 2026
Poweradmin v4.3.2 Vulnerability: Host Header Injection in Authentication FlowsEarly warning: Poweradmin v4.3.2 reportedly has a host header injection vulnerability in authentication flows.
EARLY WARNINGGEMJULY 2026
oauth2 Gem <=2.0.21 Vulnerability: Bearer Token Leak RiskEarly warning: oauth2 gem <=2.0.21 may leak bearer tokens due to a protocol-relative redirect issue.
EARLY WARNINGGEMJULY 2026
OAuth2 Gem Vulnerability: Bearer Token Leak via Protocol-Relative RedirectEarly warning: OAuth2 gem <=2.0.21 may leak bearer tokens due to a protocol-relative redirect issue.
EARLY WARNINGGEMJULY 2026
OAuth Ruby Gem <=1.1.5 Reportedly Exposes Signed Request MetadataEarly warning: OAuth Ruby gem <=1.1.5 may expose signed request metadata due to cross-origin token-request redirects.
EARLY WARNINGGEMJULY 2026
OAuth Gem for Ruby: Cross-Origin Redirects May Expose MetadataEarly warning: OAuth gem for Ruby <=1.1.5 may expose signed request metadata in cross-origin redirects.
EARLY WARNINGCARGOJULY 2026
lettre Rust Crate TLS Bug May Expose SMTP DataPotentially critical vulnerability in lettre Rust crate could allow SMTP interception.
EARLY WARNINGCARGOJULY 2026
Potential TLS Verification Bug in Rust 'lettre' PackageEarly warning: An inverted-boolean bug in Rust 'lettre' may disable TLS hostname verification.
EARLY WARNINGMAVENJULY 2026
appium/java-client Maven Package Under Investigation for Network Pivot ThreatEarly warning: appium/java-client Maven package may allow network pivoting via unvalidated redirects.
EARLY WARNINGNPMJULY 2026
PROCON-WEB SCADA Endpoint Vulnerability: Early WarningEarly warning of a critical vulnerability in PROCON-WEB SCADA allowing SQL injection.
EARLY WARNINGWORDPRESSJULY 2026
SMS Alert WooCommerce Plugin Vulnerable to Account TakeoverSMS Alert WooCommerce plugin <=3.9.7 reportedly vulnerable to Authentication Bypass via billing_phone parameter.
CONFIRMEDNPMJULY 2026
SiYuan Desktop <= v3.7.2 Vulnerabilities: Critical CVEs DiscoveredSiYuan desktop <= v3.7.2 contains critical vulnerabilities allowing code execution and SQL injection.
CONFIRMEDPHPJULY 2026
vBulletin 5.x and 6.x Critical RCE Vulnerability: CVE-2026-61511vBulletin 5.x through 5.7.5 and 6.x through 6.2.1 affected by critical eval injection vulnerability allowing unauthenticated RCE.
EARLY WARNINGCISA_KEVJULY 2026
Fortinet FortiOS Vulnerability Under Investigation: Early WarningEarly warning: Fortinet FortiOS may have a vulnerability allowing exposure of sensitive info if already compromised.
CONFIRMEDNPMJULY 2026
Arista VeloCloud Orchestrator OS Command Injection Vulnerability ExploitedArista VeloCloud Orchestrator on-premises versions contain a critical OS command injection vulnerability (CVE-2026-16812) exploited in the wild.
CONFIRMEDMAVENJULY 2026
Fastjson 1.x RCE Vulnerability Targeted in AttacksCritical remote code execution vulnerability in Alibaba's Fastjson JSON library for Java is being actively exploited.
EARLY WARNINGNPMJULY 2026
SiYuan Software Supply-Chain Vulnerability Under InvestigationSiYuan before v3.7.2 reportedly contains a critical vulnerability allowing remote code execution and admin takeover.
EARLY WARNINGCARGOJULY 2026
aws-smithy-http-server <= 0.66.4 Vulnerable to Slowloris DoSaws-smithy-http-server <= 0.66.4 reportedly allows unauthenticated Slowloris denial of service due to missing timeouts and connection limits.
EARLY WARNINGCARGOJULY 2026
aws-smithy-http-server <= 0.66.4 Vulnerable to Slowloris DoSaws-smithy-http-server <= 0.66.4 reportedly allows unauthenticated Slowloris denial of service.
EARLY WARNINGNPMJULY 2026
Quasar npm Package <=2.20.1: Prototype Pollution VulnerabilityEarly warning: Quasar npm package <=2.20.1 may be vulnerable to prototype pollution through its extend() utility.
EARLY WARNINGNPMJULY 2026
Quasar npm Package Vulnerable to Prototype Pollution: Early WarningEarly warning: Quasar npm package version 2.20.1 may be vulnerable to prototype pollution through its extend() utility.
EARLY WARNINGNPMJULY 2026
shescape npm Package Vulnerability: Shell Injection Risk on WindowsEarly warning: shescape npm package is under investigation for a shell injection vulnerability on Windows with CMD.
EARLY WARNINGNPMJULY 2026
Shescape npm Package Vulnerability: Shell Injection on Windows CMDEarly warning of a high-severity vulnerability in Shescape npm package. Shell injection possible on Windows CMD.
EARLY WARNINGPYPIJULY 2026
AWS API MCP Server Security Policy Bypass Under InvestigationEarly warning: AWS API MCP Server may silently bypass security policies due to initialization failure.
EARLY WARNINGNPMJULY 2026
blaze-server HTTP/1.1 Trailer Field Vulnerability: Early WarningEarly warning: blaze-server may merge HTTP/1.1 chunked-body trailer fields into Request.headers, allowing header injection.
EARLY WARNINGMAVENJULY 2026
blaze-server Header-Sanitization Bypass: Early WarningEarly warning: blaze-server may allow header injection via chunked-body trailers.
EARLY WARNINGNPMJULY 2026
sm-crypto npm Package: Predictable SM2 Key Generation VulnerabilityEarly warning: sm-crypto npm package reportedly uses predictable RNG for SM2 key generation.
EARLY WARNINGNPMJULY 2026
sm-crypto npm Package Vulnerability: Predictable SM2 Key GenerationEarly warning: sm-crypto npm package uses predictable RNG for SM2 key generation. Assess your exposure now.
EARLY WARNINGCARGOJULY 2026
Hubuum Client Library: Potential Sensitive Data Exposure Through DiagnosticsEarly warning: Hubuum client library may expose sensitive data via diagnostics. Upgrade to 0.6.1 and review logs.
EARLY WARNINGCARGOJULY 2026
Hubuum Client Library Vulnerability: Authenticated Requests May Escape Base PathEarly warning: Hubuum client library for Rust may expose sensitive data through redirects.
EARLY WARNINGGOJULY 2026
Integer Overflow Vulnerability in frp SSH Tunnel GatewayAn integer-overflow vulnerability in the frp server's SSH Tunnel Gateway may allow unauthenticated remote denial of service.
EARLY WARNINGGOJULY 2026
Integer Overflow Vulnerability in frp SSH Tunnel GatewayAn integer-overflow vulnerability in the frp server's SSH Tunnel Gateway may allow unauthenticated denial of service.
EARLY WARNINGMAVENJULY 2026
OpenDJ SASL PLAIN Authentication Vulnerability: Early WarningEarly warning of a potential vulnerability in OpenDJ SASL PLAIN authentication mechanism that may allow privilege escalation.
EARLY WARNINGMAVENJULY 2026
OpenDJ SASL PLAIN Vulnerability: Critical CVE Under InvestigationEarly warning: OpenDJ SASL PLAIN may allow privilege escalation. Assess your exposure now.
EARLY WARNINGMAVENJULY 2026
OpenDJ DSMLv2 Gateway Vulnerability: SSRF, File Read, DoSEarly warning: OpenDJ DSMLv2 SOAP gateway may allow SSRF, local file read, and DoS. Upgrade to version 5.1.2.
EARLY WARNINGNPMJULY 2026
Budibase REST Datasource Vulnerability: Potential Credential TheftEarly warning: Budibase may expose REST datasource credentials to unauthenticated attackers.
EARLY WARNINGNPMJULY 2026
Critical SQL Injection Vulnerability Reported in Budibase MySQL IntegrationEarly warning: A critical SQL injection vulnerability has been reported in Budibase's MySQL integration.
EARLY WARNINGNPMJULY 2026
Budibase Worker Service Vulnerability: Unauthorized Access RiskEarly warning of a potential vulnerability in Budibase worker service allowing unauthorized access to tenant groups.
EARLY WARNINGMAVENJULY 2026
OpenAM: Pre-authentication Remote Code Execution VulnerabilityEarly warning: OpenAM <=16.1.1 reportedly allows unauthenticated RCE via XML endpoint.
EARLY WARNINGPYPIJULY 2026
Open WebUI Package Vulnerability: Potential File Access ElevationEarly warning of a potential vulnerability in Open WebUI allowing file access elevation.
EARLY WARNINGPYPIJULY 2026
Open WebUI Package Vulnerability: Potential Write/Delete Access RiskEarly warning: Open WebUI package may allow read-only file access to be upgraded to write/delete.
EARLY WARNINGGOJULY 2026
Cloudreve WOPI PUT_RELATIVE Path Traversal Vulnerability AlertEarly warning: Cloudreve's WOPI PUT_RELATIVE handler may allow path traversal and arbitrary file creation.
EARLY WARNINGGOJULY 2026
Cloudreve WOPI PUT_RELATIVE Path Traversal Vulnerability AlertEarly warning: Cloudreve's WOPI PUT_RELATIVE handler may allow arbitrary file creation via path traversal.
EARLY WARNINGPYPIJULY 2026
Open WebUI Cache Misconfiguration: Potential Cross-User Model ExposureEarly warning: Open WebUI's get_all_models handlers may expose user model lists due to a cache misconfiguration.
EARLY WARNINGPYPIJULY 2026
Open WebUI Cache Misconfiguration: Cross-User Model-List ExposureEarly warning: Open WebUI may expose user-specific model lists to other authenticated users due to a caching misconfiguration.
EARLY WARNINGPYPIJULY 2026
Open WebUI Vulnerability: Potential RCE via PyodideEarly warning of a potential remote code execution vulnerability in Open WebUI via Pyodide.
EARLY WARNINGGOJULY 2026
getkin/kin-openapi Package Vulnerability: Authentication Bypass ReportedEarly warning: getkin/kin-openapi may allow unauthenticated requests due to a nil AuthenticationFunc issue.
EARLY WARNINGGOJULY 2026
getkin/kin-openapi Authentication Bypass Vulnerability: Early WarningEarly warning of a high-severity authentication bypass vulnerability in getkin/kin-openapi. Upgrade to a fixed version.
EARLY WARNINGCARGOJULY 2026
Post-auth Remote Panic Vulnerability in russh 0.62.2Early warning: russh 0.62.2 may allow post-auth remote panic via pty-req with more than 130 terminal-mode records.
EARLY WARNINGCARGOJULY 2026
Pre-auth Panic Vulnerability in russh 0.62.2 Under InvestigationEarly warning of a pre-authentication denial-of-service vulnerability in russh 0.62.2 that could allow remote panic.
EARLY WARNINGCARGOJULY 2026
Pre-auth Denial-of-Service Vulnerability Reported in russh 0.62.2Early warning: russh 0.62.2 may be vulnerable to pre-auth DoS via malformed SSH messages.
EARLY WARNINGPYPIJULY 2026
GitPython Vulnerability: Section-Name Injection Risk Under InvestigationEarly warning: GitPython <= 3.1.52 may be vulnerable to section-name injection, potentially enabling remote code execution.
EARLY WARNINGPYPIJULY 2026
GitPython <= 3.1.52: Section-Name Injection Vulnerability Under InvestigationEarly warning: GitPython <= 3.1.52 may allow remote code execution via section-name injection. Upgrade to mitigate.
EARLY WARNINGNPMJULY 2026
Potential Remote Code Execution in velocityjs v2.1.6: Early WarningEarly warning of a reported Remote Code Execution vulnerability in velocityjs v2.1.6 affecting server-side template rendering.
EARLY WARNINGNPMJULY 2026
velocityjs npm Package Vulnerability: What We KnowEarly warning of a critical vulnerability in velocityjs npm package. Assess your exposure now.
EARLY WARNINGNUGETJULY 2026
Integer Overflow in ImageMagick JNX Decoder: Potential Security RiskEarly warning: Integer overflow in ImageMagick JNX decoder may cause heap buffer over-write on 32-bit platforms.
EARLY WARNINGNUGETJULY 2026
ImageMagick Package Vulnerability: Heap Buffer Over-Write in fx OperationEarly warning of a potential heap buffer over-write vulnerability in ImageMagick's fx operation. Monitor for updates.
EARLY WARNINGGEMJULY 2026
Trix Editor Vulnerability: Stored XSS via HTML PasteEarly warning: Trix editor versions prior to 2.1.18 may be vulnerable to stored XSS. Upgrade recommended.
EARLY WARNINGNUGETJULY 2026
Microsoft Kiota Path Traversal Vulnerability: Early WarningEarly warning: Microsoft Kiota package may be vulnerable to path traversal attacks.
EARLY WARNINGNUGETJULY 2026
Microsoft Kiota Nuget Package Path Traversal Vulnerability Under InvestigationEarly warning: Microsoft Kiota nuget package has a reported path traversal vulnerability due to a percent-encoding bypass.
EARLY WARNINGNPMJULY 2026
seroval npm Package Type Confusion Issue: Early WarningEarly warning of a type confusion issue in seroval npm package versions <1.5.3, potentially allowing attacker-controlled deserialization side effects.
EARLY WARNINGNUGETJULY 2026
Microsoft Kiota Package Compromised via Command Injection VulnerabilityEarly warning: Microsoft Kiota package may have been compromised through a command injection vulnerability.
EARLY WARNINGNUGETJULY 2026
Microsoft Kiota Package Reportedly Compromised via Command InjectionEarly warning: Microsoft Kiota package may have been compromised through a command injection vulnerability.
EARLY WARNINGNUGETJULY 2026
Microsoft Kiota Package Reportedly Compromised via Command InjectionEarly warning: Microsoft Kiota package may have been compromised through a command injection vulnerability.
EARLY WARNINGNUGETJULY 2026
Microsoft Kiota Package Vulnerability: Command Injection ThreatEarly warning on a Microsoft Kiota package vulnerability allowing command injection. Check if you are affected and mitigation steps.
EARLY WARNINGNUGETJULY 2026
Microsoft Kiota Path Traversal Vulnerability: Early WarningEarly warning of a potential path traversal vulnerability in Microsoft Kiota affecting Copilot plugin manifests.
EARLY WARNINGNUGETJULY 2026
Microsoft Kiota Nuget Package Path/URL Injection VulnerabilityEarly warning of a potential path/URL injection vulnerability in Microsoft Kiota nuget package versions prior to 1.32.4.
EARLY WARNINGNUGETJULY 2026
Microsoft Kiota Path Injection Vulnerability: What You Need to KnowEarly warning of a path injection vulnerability in Microsoft Kiota affecting specific versions.
EARLY WARNINGNUGETJULY 2026
Kiota PHP Code Generator Vulnerable to Code Injection AttackEarly warning: Kiota PHP code generator may be vulnerable to code injection. Upgrade and review generated code.
EARLY WARNINGPYPIJULY 2026
Kiota Python Code Generator Vulnerable to Arbitrary Code ExecutionEarly warning: Kiota Python code generator may execute arbitrary code from malicious OpenAPI specs.
EARLY WARNINGNPMJULY 2026
@better-auth/scim npm Package: Account Takeover RiskEarly warning: @better-auth/scim npm package may have account takeover and stale access issues.
EARLY WARNINGPYPIJULY 2026
mrmustard 0.7.4 PyPI Package Compromised: Credential Stealer AlertEarly warning: mrmustard 0.7.4 on PyPI reportedly steals SSH, AWS, and Kubernetes credentials.
EARLY WARNINGNUGETJULY 2026
Use-After-Free Vulnerability in ImageMagick's FormatMagickCaptionEarly warning: A use-after-free vulnerability in ImageMagick's FormatMagickCaption method is under investigation.
EARLY WARNINGNUGETJULY 2026
ImageMagick HTML Encoder Code Injection VulnerabilityAn incomplete fix of CVE-2026-25797 can result in code injection in the HTML encoder of the ImageMagick package.
EARLY WARNINGNUGETJULY 2026
ImageMagick NuGet Package: Use-After-Free Vulnerability Under InvestigationEarly warning: ImageMagick NuGet package reportedly has a use-after-free vulnerability. Monitor for updates.
EARLY WARNINGNPMJULY 2026
9router npm Package Under Investigation for Critical Supply-Chain VulnerabilitiesEarly warning: 9router npm package reportedly contains critical vulnerabilities allowing remote code execution.
EARLY WARNINGNPMJULY 2026
Cal.com Vulnerability: Critical Remote Code Execution RiskEarly warning: Cal.com before 5.9.9 may be vulnerable to unauthenticated remote code execution.
EARLY WARNINGWORDPRESSJULY 2026
SAML SSO Login WordPress Plugin Vulnerable to Authentication BypassEarly warning: SAML SSO Login WordPress plugin <= 5.4.4 reportedly vulnerable to Authentication Bypass, allowing unauthenticated access.
EARLY WARNINGNPMJULY 2026
SoftVC VITS npm Package Path Traversal Vulnerability Under InvestigationEarly warning: SoftVC VITS npm package may contain a critical path traversal vulnerability allowing file exfiltration.
EARLY WARNINGNPMJULY 2026
h2oGPT <=0.2.1 Path Traversal Vulnerability: Early WarningEarly warning of a critical path traversal vulnerability in h2oGPT <=0.2.1, potentially leading to remote code execution.
EARLY WARNINGNPMJULY 2026
next-auth npm Package Configuration Error: Potential Authentication BypassEarly warning: next-auth npm package may allow unauthenticated access due to configuration error.
EARLY WARNINGNPMJULY 2026
Email Normalizer Vulnerability in Auth.js: Potential Account Takeover RiskEarly warning of a vulnerability in Auth.js email normalizer that may allow account takeover.
EARLY WARNINGNPMJULY 2026
Auth.js Email Normalizer Vulnerability: Early WarningEarly warning of a high-severity vulnerability in Auth.js email normalizer that may allow account takeover.
CONFIRMEDNPMJULY 2026
Bold Reports Standalone Report Designer <= 14.1.11 Vulnerability ThreatCritical vulnerability in Bold Reports Standalone Report Designer <= 14.1.11 allows unauthorized file access.
EARLY WARNINGNPMJULY 2026
Bold Reports Standalone Report Designer Path Traversal Vulnerability AlertEarly warning: Bold Reports Standalone Report Designer <14.1.12 may allow unauthenticated file read via SVG processing.
CONFIRMEDNPMJULY 2026
SiYuan before v3.7.2: Critical Stored XSS and Auth Bypass VulnerabilitiesSiYuan before v3.7.2 contains critical stored XSS and missing authorization vulnerabilities. Upgrade to v3.7.2 or later.
EARLY WARNINGWORDPRESSJULY 2026
MountDev AI MCP Connector for WordPress: Critical Vulnerability ReportedEarly warning: MountDev AI MCP Connector for WordPress <=1.6.1 may allow unauthenticated access to admin-level functions.
EARLY WARNINGWORDPRESSJULY 2026
Customer Support Ticket System & Helpdesk Plugin for WordPress Under InvestigationEarly warning: potential code injection vulnerability in WordPress plugin <=6.0.5
EARLY WARNINGMAVENJULY 2026
fastjson RCE Vulnerability (GHSA-CRF3-V9RR-V7HJ): Early WarningEarly warning: fastjson versions 1.2.68 to 1.2.83 may have a remote code execution vulnerability. Upgrade or apply a patch if available.
EARLY WARNINGNPMJULY 2026
n8n npm Package Vulnerability: Unauthenticated Endpoint Exposes Test WebhooksEarly warning: n8n npm package has an unauthenticated endpoint allowing cancellation of any user's active test webhook.
EARLY WARNINGNPMJULY 2026
n8n npm Package Vulnerability: Improper Authorization DetectedEarly warning: n8n npm package has an improper authorization vulnerability affecting versions <2.28.0.
EARLY WARNINGNPMJULY 2026
n8n npm Package Vulnerability: Improper Authorization ReportedEarly warning: n8n npm package has an improper authorization vulnerability affecting versions <2.28.0.
EARLY WARNINGNPMJULY 2026
n8n npm Package Vulnerability: External Secrets Exposure RiskEarly warning: n8n npm package vulnerability may expose external secrets. Upgrade to version 2.27.4 or 2.28.1 or later.
EARLY WARNINGNPMJULY 2026
n8n npm Package Privilege Escalation Vulnerability Under InvestigationEarly warning: n8n npm package reportedly allows SSO privilege escalation to instance owner under specific conditions.
EARLY WARNINGMAVENJULY 2026
netty maven Package WebSockets Handshaker Vulnerability: Early WarningEarly warning: netty maven WebSockets V07/V08 handshaker missing validation, enabling potential HTTP request smuggling attacks.
EARLY WARNINGMAVENJULY 2026
Netty WebSockets V07/V08 Handshaker Vulnerability: Early WarningEarly warning: Netty WebSockets V07/V08 handshaker may allow HTTP request smuggling and protocol-confusion attacks.
EARLY WARNINGMAVENJULY 2026
Netty OCSP Response Validation Issue: Early WarningEarly warning of a critical vulnerability in Netty's OcspClient affecting OCSP response validation.
EARLY WARNINGMAVENJULY 2026
Netty's OcspClient Vulnerability: Potential Replay AttacksEarly warning: Netty's OcspClient may allow replay attacks due to missing CertificateID validation.
EARLY WARNINGGITHUB-ACTIONSJULY 2026
GitHub Actions Abused to Exploit CVE-2026-41940 in cPanel and WHMEarly warning: GitHub Actions reportedly abused to exploit CVE-2026-41940 in cPanel and WHM, stealing server credentials.
EARLY WARNINGNPMJULY 2026
Windmill Path Traversal Vulnerability Exploited in the WildHigh-severity Windmill flaw CVE-2026-29059 allows unauthenticated file read, actively exploited.
CONFIRMEDNPMJULY 2026
n8n npm Package SSRF Vulnerability: Critical Update Requiredn8n versions before 1.123.64 have a confirmed SSRF vulnerability. Upgrade now.
EARLY WARNINGNPMJULY 2026
Potential Shell Sandbox Bypass in @n8n/computer-use npm PackageEarly warning: @n8n/computer-use npm package may allow unrestricted access to host filesystem and network.
EARLY WARNINGNPMJULY 2026
SharePoint Vulnerability CVE-2026-50522 Under InvestigationEarly warning: SharePoint vulnerability CVE-2026-50522 is reportedly being exploited to steal machine keys.
EARLY WARNINGNPMJULY 2026
Microsoft SharePoint Vulnerability CVE-2026-50522 Under InvestigationEarly warning: Microsoft SharePoint reportedly contains a deserialization vulnerability allowing remote code execution.
CONFIRMEDCISA_KEVJULY 2026
Check Point SmartConsole Critical Vulnerability: Authentication BypassCheck Point SmartConsole has a critical authentication bypass vulnerability allowing full admin access.
EARLY WARNINGGEMJULY 2026
Possible XSS Vulnerability in rails-html-sanitizer GemEarly warning: a potential cross-site scripting vulnerability in rails-html-sanitizer gem with certain SVG configurations.
EARLY WARNINGGEMJULY 2026
Possible XSS Vulnerability in rails-html-sanitizer Gem: Early WarningEarly warning of a potential cross-site scripting vulnerability in rails-html-sanitizer gem affecting certain configurations.
EARLY WARNINGGEMJULY 2026
Loofah Gem Vulnerability: Potential XSS via Split javascript: URIsEarly warning on a potential XSS vulnerability in Loofah gem's allowed_uri? method due to split javascript: URIs.
EARLY WARNINGGEMJULY 2026
Loofah HTML Sanitizer Vulnerability: SVG href Attribute BypassEarly warning of a vulnerability in Loofah's HTML sanitizer affecting SVG href attributes.
EARLY WARNINGGEMJULY 2026
Loofah HTML5 Sanitizer Vulnerability: SVG href Attribute BypassEarly warning: Loofah HTML5 sanitizer vulnerability allows SVG href attribute bypass, potentially leading to dangerous content execution.
EARLY WARNINGNPMJULY 2026
typeorm npm Package Under Investigation for Critical VulnerabilityEarly warning: typeorm npm package may allow code execution via unsanitized template literals.
EARLY WARNINGNPMJULY 2026
Potential Code Injection in typeorm npm Package: Early WarningEarly warning of a potential code injection vulnerability in the typeorm npm package. Assess your exposure now.
EARLY WARNINGGOJULY 2026
Gitea Vulnerability: Cached Permission Check Allows Full Write AccessEarly warning: Gitea 1.25.5 has a vulnerability allowing full repository write access.
CONFIRMEDNPMJULY 2026
'keep' npm Package SSRF Vulnerability: Critical Threat ConfirmedConfirmed critical vulnerability in 'keep' npm package allows SSRF attacks, enabling credential theft and network reconnaissance.
EARLY WARNINGNPMJULY 2026
lmdeploy API Server Vulnerability: Potential SSRF ThreatEarly warning: lmdeploy's API server may have a critical SSRF vulnerability allowing access to internal services.
EARLY WARNINGGOJULY 2026
Gitea's restore-repo Command Vulnerable to Local File InclusionEarly warning: Gitea's restore-repo command may allow local file inclusion via file:// URI.
EARLY WARNINGGOJULY 2026
Gitea Local File Inclusion Vulnerability Under InvestigationEarly warning: Gitea's restore-repo command may allow local file inclusion via file:// URI.
EARLY WARNINGGOJULY 2026
Gitea's RSS/Atom Feed Handlers May Expose Private ContentEarly warning: Gitea's RSS/Atom feed handlers may bypass API-token scope and expose private content.
EARLY WARNINGGOJULY 2026
Gitea RSS/Atom Feed Handlers Bypass API-Token Scope EnforcementEarly warning: Gitea's RSS/Atom feed handlers may allow private content access via API tokens.
EARLY WARNINGGOJULY 2026
Gitea Vulnerability: Public Tokens May Affect Private PR BranchesEarly warning on a Gitea vulnerability allowing public tokens to update private branches.
EARLY WARNINGGOJULY 2026
Gitea PAT Scope Enforcement Bypass: Private Repo Commit Data LeakEarly warning: Gitea PAT scope enforcement bypass may leak private repo commit data.
EARLY WARNINGGOJULY 2026
Gitea Docker Images: Potential User Impersonation VulnerabilityEarly warning: Gitea Docker images may allow user impersonation via X-WEBAUTH-USER header.
EARLY WARNINGGOJULY 2026
Gitea API Vulnerability: Potential Privilege Escalation via Access TokensEarly warning: Gitea API may allow privilege escalation via access token scope escalation. Upgrade to version 1.27.0.
EARLY WARNINGGOJULY 2026
Gitea API Endpoint Vulnerability: Potential Privilege EscalationEarly warning of a potential privilege escalation vulnerability in Gitea's API endpoint for creating Personal Access Tokens.
EARLY WARNINGGOJULY 2026
Gitea Debian Package Parser Vulnerabilities: Early WarningEarly warning of high severity vulnerabilities in Gitea's Debian package parser leading to potential denial of service.
EARLY WARNINGGOJULY 2026
Gitea Attachment Re-linking Issue: Potential Exposure of Private ContentEarly warning on a potential vulnerability in Gitea that could expose private attachment content.
EARLY WARNINGGOJULY 2026
Gitea Remember-Me Token Vulnerability: Persistent Attacker SessionsEarly warning: Gitea's Remember-Me token validation logic may not invalidate attacker sessions.
EARLY WARNINGGOJULY 2026
Gitea Web Release Edit Form Vulnerability Under InvestigationEarly warning: Gitea web release edit form may allow forbidden extensions, tracked as CVE-2025-68939 and GHSA-25GQ-J9JX-43PG.
EARLY WARNINGGITHUB-ACTIONSJULY 2026
Gitea Webhook Issue: Potential Ongoing Data ExfiltrationReportedly, Gitea webhooks created by collaborators may continue firing after access revocation, leading to potential data exfiltration.
EARLY WARNINGGITHUB-ACTIONSJULY 2026
Gitea Webhook Delivery Issue: Potential Ongoing Exfiltration of Private Repo ContentEarly warning: Gitea's webhooks may continue firing after collaborator access is revoked, potentially leading to exfiltration of private repository content.
EARLY WARNINGPYPIJULY 2026
GitPython Package Reportedly Vulnerable to Command InjectionEarly warning: GitPython package versions 3.1.47 through 3.1.50-42 are under investigation for a command injection vulnerability.
EARLY WARNINGPYPIJULY 2026
GitPython Vulnerable to Command Injection: Early WarningGitPython versions 3.1.47 through 3.1.50-42 reportedly vulnerable to command injection via long-option prefix abbreviation bypass.
EARLY WARNINGNPMJULY 2026
SVGO's removeScripts Plugin Potentially Leaves Executable Scripts IntactEarly warning: SVGO's removeScripts plugin may not remove all executable scripts, posing potential XSS risks.
EARLY WARNINGNPMJULY 2026
@vitest/browser npm Package Vulnerability: Early WarningEarly warning of a vulnerability in @vitest/browser npm package allowing arbitrary file operations.
EARLY WARNINGNPMJULY 2026
Potential Vulnerability in @vitest/browser npm Package: Early WarningEarly warning of a potential vulnerability in @vitest/browser npm package that may allow unauthorized file access.
EARLY WARNINGNPMJULY 2026
@sigstore/oci npm Package Credential Exposure Issue: Early WarningEarly warning: @sigstore/oci npm package may expose registry credentials due to a substring match vulnerability.
EARLY WARNINGMAVENJULY 2026
Jackson-databind Vulnerability: @JsonIgnore Bypassed with PropertyNamingStrategyEarly warning: Jackson-databind vulnerability allows bypassing @JsonIgnore on Record properties.
EARLY WARNINGMAVENJULY 2026
jackson-databind Java Library Vulnerability: Early WarningEarly warning: jackson-databind Java library has a vulnerability that may allow bypassing @JsonIgnore on Record properties.
EARLY WARNINGNPMJULY 2026
Potential Denial of Service in OpenTelemetry JaegerPropagatorEarly warning of a potential denial of service vulnerability in the OpenTelemetry JaegerPropagator.
EARLY WARNINGNPMJULY 2026
Potential Denial of Service in OpenTelemetry JaegerPropagatorEarly warning: OpenTelemetry JaegerPropagator may be vulnerable to denial of service via malformed headers.
EARLY WARNINGNPMJULY 2026
fast-uri npm Package Vulnerability: Host Confusion via Failed IDN CanonicalizationEarly warning: fast-uri npm package versions >=2.3.1, <=4.0.0 may lead to host-based policy desync and unintended routing.
EARLY WARNINGNUGETJULY 2026
Potential Denial of Service Vulnerability in .NET ASP.NET Core SignalREarly warning of a reported denial of service vulnerability in.NET ASP.NET Core SignalR affecting specific versions.
EARLY WARNINGNUGETJULY 2026
Potential.NET SDK Container Build Tampering Vulnerability: Early WarningEarly warning of a potential tampering vulnerability in.NET SDK container image builds. Assess your exposure now.
EARLY WARNINGNUGETJULY 2026
Elevation of Privilege Vulnerability in.NET Core Authentication HandlerEarly warning of a potential elevation of privilege vulnerability in.NET Core authentication handler affecting.NET 8, 9, and 10.
EARLY WARNINGNUGETJULY 2026
Elevation of Privilege Vulnerability in.NET ASP.NET Core AuthenticationEarly warning: elevation of privilege vulnerability in.NET ASP.NET Core authentication handler due to improper parsing.
EARLY WARNINGNUGETJULY 2026
Elevation of Privilege Vulnerability in.NET Core Authentication HandlerEarly warning of a potential elevation of privilege vulnerability in.NET Core authentication handler affecting.NET 8, 9, and 10.
EARLY WARNINGNUGETJULY 2026
.NET 8, 9, 10 XML Encryption DoS Vulnerability Under InvestigationEarly warning: A denial of service vulnerability in.NET 8, 9, 10 XML encryption is under investigation. Upgrade to patched versions.
EARLY WARNINGNUGETJULY 2026
Elevation of Privilege Vulnerability in.NET WPF Under InvestigationEarly warning: An elevation of privilege vulnerability in.NET WPF is under investigation. Affected components and recommended actions are provided.
EARLY WARNINGWORDPRESSJULY 2026
Ninja Forms WordPress Plugin Under Investigation for Critical VulnerabilityEarly warning: Ninja Forms plugin for WordPress Multisite has a critical authorization vulnerability.
EARLY WARNINGWORDPRESSJULY 2026
Ninja Forms WordPress Plugin: Critical XSS Vulnerability ReportedEarly warning: Ninja Forms WordPress plugin versions 3.10.4 through 3.14.9 reportedly contain a critical unauthenticated stored XSS vulnerability.
EARLY WARNINGGEMJULY 2026
Loofah Gem Vulnerability: Potential XSS via Split JavaScript URIsEarly warning: Loofah gem's allowed_uri? method may not detect split javascript: URIs, leading to potential XSS.
EARLY WARNINGGEMJULY 2026
Loofah Gem Vulnerability: Potential XSS via Split JavaScript URIsEarly warning on Loofah gem's allowed_uri? method not detecting split javascript: URIs, leading to potential XSS.
EARLY WARNINGPACKAGISTJULY 2026
Grav 2.0.4 Remote Code Execution Vulnerability Under InvestigationEarly warning: Grav 2.0.4 reportedly contains a critical remote code execution vulnerability.
EARLY WARNINGNPMJULY 2026
Grav api Plugin Vulnerability: Potential Account Takeover RiskEarly warning of a critical vulnerability in Grav api plugin that may allow account takeover.
CONFIRMEDNPMJULY 2026
ServiceNow AI Platform Vulnerability CVE-2026-6875 Exploited in the WildServiceNow AI Platform vulnerability CVE-2026-6875 is being actively exploited for remote code execution.
CONFIRMEDNPMJULY 2026
Langflow RCE Exploited to Deploy ENCFORGE Ransomware on AI InfrastructureLangflow RCE vulnerability CVE-2026-0770 exploited in the wild to deploy ENCFORGE ransomware targeting AI model files.
EARLY WARNINGWORDPRESSJULY 2026
Easy Form Builder WordPress Plugin Vulnerable to Critical Privilege EscalationEarly warning: Easy Form Builder plugin <=4.0.11 may allow unauthenticated privilege escalation.
EARLY WARNINGCISA_KEVJULY 2026
DD-WRT Buffer Overflow Vulnerability Under InvestigationEarly warning: DD-WRT reportedly contains a buffer overflow vulnerability that could allow code execution.
EARLY WARNINGNUGETJULY 2026
Denial of Service Vulnerability in.NET XML EncryptionEarly warning of a denial of service vulnerability in.NET XML encryption affecting.NET 8, 9, and 10.
EARLY WARNINGNUGETJULY 2026
Denial of Service Vulnerability Reported in.NET 8, 9, 10 XML EncryptionEarly warning: A denial of service vulnerability is reportedly affecting.NET 8, 9, and 10 XML encryption.
EARLY WARNINGNUGETJULY 2026
.NET Security Feature Bypass Vulnerability Under InvestigationEarly warning:.NET 8,.NET 9, and.NET 10 may have a security feature bypass vulnerability in TLS/SSL connections.
EARLY WARNINGNUGETJULY 2026
.NET Security Feature Bypass Vulnerability Under InvestigationEarly warning:.NET 8,.NET 9, and.NET 10 may have a security feature bypass vulnerability in TLS/SSL processing.
EARLY WARNINGNUGETJULY 2026
.NET Denial of Service Vulnerability: Early WarningEarly warning of a potential denial of service vulnerability in.NET 8,.NET 9, and.NET 10.
EARLY WARNINGNUGETJULY 2026
Denial of Service Vulnerability Reported in.NET 8, 9, 10Early warning: A denial of service vulnerability is reportedly affecting.NET 8, 9, and 10.
EARLY WARNINGNUGETJULY 2026
Reported .NET Security Feature Bypass Vulnerability: What We KnowEarly warning of a reported security feature bypass vulnerability in.NET 8,.NET 9, and.NET 10 XML encryption.
EARLY WARNINGNUGETJULY 2026
.NET Security Feature Bypass Vulnerability ReportedReportedly, a security feature bypass vulnerability exists in.NET 8,.NET 9, and.NET 10 XML encryption.
EARLY WARNINGNUGETJULY 2026
.NET XML Processing Denial of Service VulnerabilityAn unverified denial of service vulnerability in.NET XML processing is under investigation.
EARLY WARNINGNUGETJULY 2026
Potential.NET XML Denial of Service Vulnerability Under InvestigationEarly warning: A denial of service vulnerability in.NET XML processing is under investigation. Affected components and recommended actions.
EARLY WARNINGNUGETJULY 2026
.NET Denial of Service Vulnerability: Early WarningEarly warning of a denial of service vulnerability in.NET runtime cryptography layer.
EARLY WARNINGNPMJULY 2026
AVideo < 29.0: Critical CVE Under Investigation - Command Injection RiskEarly warning: AVideo before 29.0 reportedly contains a critical vulnerability allowing command injection.
EARLY WARNINGNPMJULY 2026
shell-quote npm Package Vulnerability: Quadratic-complexity Denial of ServiceEarly warning: shell-quote npm package has a reported quadratic-complexity denial of service vulnerability.
EARLY WARNINGNPMJULY 2026
shell-quote npm Package Vulnerability: Quadratic-Complexity Denial of ServiceEarly warning of a high-severity vulnerability in shell-quote npm package affecting Node.js applications.
EARLY WARNINGPYPIJULY 2026
Mistune Package Vulnerability: Predictable Heading IDs RiskMistune package's toc plugin may allow attackers to inject HTML with predictable IDs, affecting multiple versions.
EARLY WARNINGPYPIJULY 2026
Pillow Package OS Command Injection Vulnerability on WindowsEarly warning of a potential OS command injection vulnerability in the Pillow package on Windows.
EARLY WARNINGNPMJULY 2026
Astro Reflected XSS Vulnerability: Early WarningEarly warning of a high severity reflected XSS vulnerability in Astro's View Transition CSS generator.
EARLY WARNINGNPMJULY 2026
brace-expansion npm Package: Potential DoS via Exponential-Time Expansionbrace-expansion npm package exhibits exponential-time behavior, leading to potential DoS attacks. Monitor and consider input validation.
EARLY WARNINGNPMJULY 2026
ktransformers npm Package Vulnerability: Early Warning IssuedEarly warning: ktransformers npm package <=0.6.3 reportedly contains a critical unauthenticated pickle deserialization vulnerability.
EARLY WARNINGNPMJULY 2026
GPT-SoVITS npm Package OS Command Injection Vulnerability Under InvestigationEarly warning: GPT-SoVITS npm package reportedly contains critical OS command injection vulnerability.
EARLY WARNINGPYPIJULY 2026
vLLM Package Vulnerability: Denial of Service RiskEarly warning of a potential denial of service vulnerability in the vLLM package.
EARLY WARNINGNPMJULY 2026
Axios formDataToJSON Vulnerability: Potential Denial of Service RiskEarly warning: Axios versions 0.28.0 and later may have uncontrolled recursion in formDataToJSON.
EARLY WARNINGNPMJULY 2026
Axios Vulnerability: Excessive Recursion in formDataToJSONEarly warning: Axios versions 0.28.0 and later may contain a denial of service vulnerability due to excessive recursion in formDataToJSON.
EARLY WARNINGPYPIJULY 2026
Pulpcore Path Traversal Vulnerability: Critical CVE-2026-12701 AlertEarly warning: Critical path traversal vulnerability found in pulpcore, affecting multiple versions.
EARLY WARNINGCJULY 2026
FreeRDP <=3.27.1 Buffer Overflow Vulnerability Under InvestigationFreeRDP <=3.27.1 reportedly contains a critical heap-based buffer overflow vulnerability.
EARLY WARNINGGEMJULY 2026
Malicious RubyGems Targeting Developer MachinesReportedly malicious versions of git_credential_manager, Dendreo, and fastlane RubyGems may compromise developer machines.
EARLY WARNINGCARGOJULY 2026
SurrealDB Vulnerability: SurrealQL Injection RiskEarly warning on SurrealDB vulnerability allowing SurrealQL injection and privilege escalation.
EARLY WARNINGGOJULY 2026
routesrv Component Exposes Sensitive Cluster Data: Early WarningEarly warning: routesrv component may expose sensitive cluster data due to lack of authentication.
CONFIRMEDWORDPRESSJULY 2026
Critical WordPress Core Flaw (CVE-2026-63030) Enables Unauthenticated RCEConfirmed: Unauthenticated attackers can execute code on vulnerable WordPress sites. Upgrade to 6.9.5 or 7.0.2.
CONFIRMEDNPMJULY 2026
Critical Vulnerability in IBM Langflow OSS: Arbitrary File WriteIBM Langflow OSS versions 1.0.0 to 1.10.0 have a critical vulnerability allowing arbitrary file writes.
CONFIRMEDNPMJULY 2026
IBM Langflow OSS Code Injection Vulnerability: Critical Threat ConfirmedCritical code injection vulnerability in IBM Langflow OSS versions up to 1.10.0 confirmed. Upgrade to 1.10.0+ to mitigate.
EARLY WARNINGPYPIJULY 2026
meta-ads-mcp Package Auth Bypass Vulnerability: Early WarningEarly warning: meta-ads-mcp package has an authentication bypass vulnerability affecting multiple versions.
EARLY WARNINGPYPIJULY 2026
plone.app.textfield Stored XSS Vulnerability: Early WarningEarly warning of a stored XSS vulnerability in plone.app.textfield affecting versions <2.0.2, <3.0.2, <4.0.1
CONFIRMEDNPMJULY 2026
Critical Vulnerability in IBM Langflow OSS: Unauthenticated User Account CreationIBM Langflow OSS versions 1.0.0 through 1.10.0 allow unauthenticated attackers to create user accounts, leading to potential RCE.
CONFIRMEDNPMJULY 2026
IBM Langflow OSS 1.0.0 to 1.10.0 Remote Code Execution VulnerabilityCritical RCE vulnerability in IBM Langflow OSS 1.0.0 to 1.10.0 allows unauthenticated attackers full remote code execution.
EARLY WARNINGMAVENJULY 2026
ArcadeDB Vulnerability Under InvestigationArcadeDB is reportedly vulnerable to privilege escalation and arbitrary file read.
EARLY WARNINGMAVENJULY 2026
ArcadeDB Privilege Escalation Vulnerability: Early WarningEarly warning of a potential privilege escalation vulnerability in ArcadeDB affecting multiple versions.
EARLY WARNINGNPMJULY 2026
Critical RCE Vulnerability in npm PackageAn unauthenticated remote attacker may be able to perform remote code execution due to incorrectly sanitized user input.
EARLY WARNINGPYPIJULY 2026
Snowflake Connector for Python TLS Hostname Verification IssueEarly warning about improper TLS hostname verification in Snowflake Connector for Python.
CONFIRMEDCISA_KEVJULY 2026
Fortinet FortiSandbox Vulnerabilities Exploited: CVE-2026-25089, CVE-2026-39808Fortinet FortiSandbox has confirmed OS command injection vulnerabilities. Upgrade to latest version.
EARLY WARNINGGEMJULY 2026
dd-trace-rb Gem Vulnerability: Improper W3C Baggage Header ParsingEarly warning: dd-trace-rb gem may lead to DoS via improper W3C baggage header parsing. Upgrade or set HTTP header limits.
EARLY WARNINGGEMJULY 2026
ViewComponent Gem Vulnerability: Reused Instances Retain Stale ContextEarly warning of a high severity vulnerability in ViewComponent gem affecting render context retention.
EARLY WARNINGGEMJULY 2026
ViewComponent around_render HTML-Safety Bypass: Early WarningEarly warning of a potential XSS vulnerability in ViewComponent due to HTML-unsafe strings in around_render.
EARLY WARNINGNPMJULY 2026
websocket-driver npm Package Vulnerability: Early WarningEarly warning of a high severity vulnerability in websocket-driver npm package. Upgrade to version 0.7.5.
EARLY WARNINGNPMJULY 2026
websocket-driver npm Package Under Investigation: Resource Limit Bypasswebsocket-driver npm package is under investigation for a resource limit bypass vulnerability when used with permessage-deflate.
EARLY WARNINGNPMJULY 2026
websocket-driver npm Package: Resource Limit Bypass via Message CompressionEarly warning: websocket-driver npm package may accept oversized messages due to a compression issue.
EARLY WARNINGGEMJULY 2026
websocket-driver Gem Vulnerability: Memory Exhaustion via Protocol Length HeadersEarly warning of a high severity vulnerability in websocket-driver gem affecting versions <0.8.1.
EARLY WARNINGGEMJULY 2026
websocket-driver Gem Vulnerability: Memory Exhaustion ThreatEarly warning of a high severity vulnerability in websocket-driver gem, potentially leading to memory exhaustion.
EARLY WARNINGNPMJULY 2026
AsyncAPI npm Packages Reportedly Infected with MalwareFive malicious versions of AsyncAPI packages were published to npm, delivering a remote access trojan.
EARLY WARNINGNPMJULY 2026
Grav API Plugin Vulnerability: Potential Account Takeover RiskEarly warning of a critical vulnerability in Grav API plugin that may enable account takeover.
CONFIRMEDCISA_KEVJULY 2026
Oracle E-Business Suite Vulnerability: Critical Threat to Oracle PaymentsOracle E-Business Suite contains a critical vulnerability allowing takeover of Oracle Payments.
EARLY WARNINGNPMJULY 2026
AsyncAPI npm Packages Compromised with Malicious PayloadReportedly, three AsyncAPI npm packages were compromised with an obfuscated dropper. Assess your exposure now.
EARLY WARNINGNPMJULY 2026
SAP Approuter HTTP Request Smuggling Vulnerability: Early WarningEarly warning of a high severity HTTP Request Smuggling vulnerability in SAP Approuter.
CONFIRMEDCISA_KEVJULY 2026
Microsoft SharePoint Server Vulnerability CVE-2026-56164: What You Need to KnowMicrosoft SharePoint Server contains a critical vulnerability allowing unauthorized privilege elevation. Patches are available.
CONFIRMEDCISA_KEVJULY 2026
SonicWall SMA1000 Appliances Exploited: CVE-2026-15410 ConfirmedSonicWall SMA1000 Appliances face high-severity code injection vulnerability CVE-2026-15410, exploited in the wild. Patch now.
EARLY WARNINGGEMJULY 2026
Decidim Gem Vulnerability: Potential SSRF via Push Subscription EndpointEarly warning: Decidim gem's push subscription endpoint may allow SSRF attacks.
EARLY WARNINGGEMJULY 2026
Decidim HTML Content Blocks Vulnerability: Potential Script ExecutionEarly warning: Decidim gem vulnerability allows admins to store arbitrary HTML/JavaScript, potentially leading to script execution in visitor's browsers.
EARLY WARNINGGITHUB-ACTIONSJULY 2026
Decidim Package Authorization Issue: Potential Data Corruption RiskEarly warning: Decidim package may allow unauthorized access to CSV census records, potentially corrupting verification data.
EARLY WARNINGGITHUB-ACTIONSJULY 2026
Decidim JWT-backed Authentication Vulnerability: Early WarningEarly warning: Decidim JWT-backed authentication can reportedly be replayed across organizations.
EARLY WARNINGGEMJULY 2026
Decidim Gem Vulnerability: Verification Documents ExposedEarly warning: Decidim gem's verification admin UI exposes documents through reusable links.
EARLY WARNINGGEMJULY 2026
Decidim Gem Vulnerability: Private Exports Accessible via Reusable LinksEarly warning: Decidim gem allows unauthorized access to private exports.
EARLY WARNINGGEMJULY 2026
Decidim Gem SQL Injection Vulnerability: Early WarningEarly warning: Decidim gem's admin user search feature may allow SQL injection.
CONFIRMEDNPMJULY 2026
jscrambler 8.14.0 npm Package Compromised: Supply Chain Attack Detailsjscrambler 8.14.0 npm package compromised with malicious preinstall hook. Rotate secrets if used.
CONFIRMEDNPMJULY 2026
PraisonAI < 4.6.78 Supply-Chain Threat: Critical Vulnerabilities ConfirmedPraisonAI versions before 4.6.78 contain critical supply-chain vulnerabilities allowing arbitrary file writes and command execution.
EARLY WARNINGGITHUB-ACTIONSJULY 2026
Windmill GitHub Action Vulnerability: Early Warning for EngineersWindmill GitHub Action <= 1.714.1 may expose script contents.
EARLY WARNINGPYPIJULY 2026
mcp-atlassian Package SSRF Vulnerability Under InvestigationReportedly, the mcp-atlassian package has an incomplete SSRF fix allowing unauthenticated SSRF. Monitor for patches.
EARLY WARNINGPYPIJULY 2026
Potential DNS-Rebinding Attack on mcp-atlassian PyPI PackageReportedly, the mcp-atlassian package on PyPI has a DNS-rebinding TOCTOU bypass of the SSRF fix. Monitor for updates.
EARLY WARNINGNPMJULY 2026
Critical Vulnerability Reported in Vikunja < 2.2.1Vikunja versions before 2.2.1 reportedly contain severe authorization flaws. Upgrade and review access controls.
EARLY WARNINGWORDPRESSJULY 2026
Instant Appointment WordPress Plugin Vulnerability (CVE-2026-15282)Potential critical vulnerability in Instant Appointment WordPress plugin <=1.2. Investigate exposure.
EARLY WARNINGWORDPRESSJULY 2026
Super Forms WordPress Plugin Vulnerable to Arbitrary File UploadSuper Forms – Drag & Drop Form Builder plugin for WordPress is reportedly vulnerable to Arbitrary File Upload, allowing remote code execution.
EARLY WARNINGCARGOJULY 2026
Rattler Package Cache Path Traversal VulnerabilityReported vulnerability in rattler_cache and py-rattler allows path traversal. Upgrade advised.
EARLY WARNINGNPMJULY 2026
Hermes WebUI Authentication Bypass Vulnerability ReportedHermes WebUI before 0.51.307 reportedly contains an authentication bypass vulnerability allowing server-side request forgery.
CONFIRMEDNPMJULY 2026
Injective npm Package Compromised: Wallet Keys and Mnemonics StolenCritical supply-chain attack on Injective npm package exfiltrated wallet secrets.
EARLY WARNINGMAVENJULY 2026
Micronaut HTTP Client Vulnerability Under InvestigationReportedly, Micronaut HTTP Client lacks redirect limit, enabling DoS. Upgrade advised.
EARLY WARNINGNPMJULY 2026
Potential Open Redirect in Waku npm PackageReportedly, the `unstable_redirect()` helper in the `waku` npm package may lead to open redirect attacks.
EARLY WARNINGNPMJULY 2026
Open Redirect Vulnerability in waku npm PackageReportedly, the waku npm package has an open redirect vulnerability via unstable_redirect() helper.
EARLY WARNINGGITHUB-ACTIONSJULY 2026
Nuclio <= 1.15.27 Vulnerability Under InvestigationNuclio <= 1.15.27 reportedly has a critical RCE vulnerability due to unsanitized inputs.
EARLY WARNINGWORDPRESSJULY 2026
Critical Vulnerability in Blocksy Companion Pro for WordPressReportedly critical unauthenticated arbitrary file upload vulnerability in Blocksy Companion Pro plugin for WordPress.
EARLY WARNINGGITHUB-ACTIONSJULY 2026
oasdiff Vulnerability: SSRF and Local File Read Risksoasdiff versions <=v1.18.0 may be vulnerable to SSRF and local file read due to improper enforcement of external refs.
EARLY WARNINGGOJULY 2026
Goploy Package Vulnerability Under InvestigationReportedly, Goploy package allows unauthorized access and remote code execution.
EARLY WARNINGGOJULY 2026
Goploy Package Vulnerability: Cross-namespace IDOR and RCE RiskEarly warning of a high-severity vulnerability in the Goploy package that may lead to remote code execution.
EARLY WARNINGNPMJULY 2026
Critical Vulnerability in openmemory/api (CVE-2026-59705)An unauthenticated access vulnerability in openmemory/api allows arbitrary memory manipulation and denial-of-service.
EARLY WARNINGNPMJULY 2026
@better-auth/sso npm Package Vulnerability: Early WarningEarly warning of a potential server-side request forgery vulnerability in @better-auth/sso npm package.
EARLY WARNINGNPMJULY 2026
OAuth Provider Refresh Token Issue: Assess Your Exposure NowEarly warning: OAuth provider's refresh token mechanism under investigation. Learn how to assess your exposure.
EARLY WARNINGNPMJULY 2026
better-auth npm Package Vulnerability: OAuth Refresh Token IssueEarly warning: better-auth npm package has a vulnerability affecting oidcProvider and mcp plugins.
EARLY WARNINGNPMJULY 2026
Potential Phoenix Framework Presence Client VulnerabilityReportedly, a vulnerability in Phoenix Framework's Presence JavaScript client may cause client-side denial of service.
EARLY WARNINGPHPJULY 2026
Suspected China-Aligned Hackers Exploit Roundcube FlawsSuspected China-aligned threat cluster reportedly exploiting Roundcube webmail software at U.S. and Canadian universities.
CONFIRMEDNPMJULY 2026
Langflow Auth Bypass Vulnerability: CVE-2026-55255 Confirmed ExploitedLangflow contains a confirmed authorization bypass vulnerability allowing attackers to execute any flow. Upgrade to the latest version.
EARLY WARNINGCARGOJULY 2026
Critical Vulnerability in halo2_gadgets Affects ZebradReportedly, a critical vulnerability in halo2_gadgets could allow double-spending and fund theft. Monitor for updates.
EARLY WARNINGNPMJULY 2026
Decompress npm Package Vulnerability Under InvestigationReportedly, the @xhmikosr/decompress npm package has a vulnerability that may allow file creation outside the target directory.
EARLY WARNINGGITHUB-ACTIONSJULY 2026
Cilium Vulnerability: Sensitive Information Disclosure and Cluster DisruptionEarly warning: Cilium is reportedly vulnerable to sensitive information disclosure and cluster disruption.
EARLY WARNINGPYPIJULY 2026
Memory-Safety Vulnerability in Open Babel's MOPAC ParserReportedly, a memory-safety vulnerability in Open Babel's MOPAC output parser may allow out-of-bounds writes. Upgrade to Open Babel 3.2.0 or later.
EARLY WARNINGMAVENJULY 2026
Apache Camel Keycloak Component Vulnerability: Early WarningEarly warning of a high severity vulnerability in Apache Camel Keycloak Component. Assess your exposure now.
EARLY WARNINGMAVENJULY 2026
Apache Camel DNS Vulnerability: SSRF Risk Due to Improper Input ValidationEarly warning of a high severity vulnerability in Apache Camel DNS component leading to SSRF risk.
EARLY WARNINGMAVENJULY 2026
Apache Camel camel-mongodb-gridfs Vulnerability: Early WarningEarly warning of a potential vulnerability in Apache Camel's camel-mongodb-gridfs component. Upgrade recommended.
EARLY WARNINGMAVENJULY 2026
Apache Camel Solr Component Vulnerability: Critical SSRF RiskEarly warning of a high-severity vulnerability in Apache Camel Solr component. Assess your exposure and mitigation steps.
EARLY WARNINGMAVENJULY 2026
Apache Camel Docling Component Vulnerability: Early WarningEarly warning of a critical vulnerability in Apache Camel Docling component. Upgrade to 4.18.3 or later.
EARLY WARNINGMAVENJULY 2026
Apache Camel PQC Component Vulnerability: Critical CVE AlertEarly warning of a critical deserialization vulnerability in Apache Camel PQC Component. Upgrade to version 4.21.0 or 4.18.3.
EARLY WARNINGMAVENJULY 2026
Apache Camel Cometd Component Vulnerability: Critical CVE AlertEarly warning of a critical vulnerability in Apache Camel Cometd Component. Upgrade to patched versions to mitigate risk.
EARLY WARNINGMAVENJULY 2026
Apache Camel Keycloak Component Vulnerability: Expired Tokens AcceptedEarly warning of a high severity vulnerability in Apache Camel Keycloak component. Expired tokens may be accepted due to missing IS_ACTIVE check.
EARLY WARNINGGOJULY 2026
Gitea Versions Before 1.26.0: Branch-Protection Bypass VulnerabilityEarly warning: Gitea versions before 1.26.0 may allow branch-protection bypass due to scanner errors.
EARLY WARNINGGOJULY 2026
Gitea Repository Creation Fields Validation Issue: Early WarningEarly warning for Gitea versions before 1.25.5: insufficient validation of repository creation fields.
EARLY WARNINGGOJULY 2026
Gitea Path Resolution Vulnerability: Assess Your Exposure NowGitea versions before 1.25.5 may mishandle path resolution. Upgrade to 1.25.5 or later.
EARLY WARNINGGOJULY 2026
Gitea OAuth2 PKCE S256 Verifier Bypass: Early WarningEarly warning of a potential vulnerability in Gitea versions before 1.25.5. Upgrade to version 1.25.5 or later.
EARLY WARNINGGOJULY 2026
Gitea OAuth2 Authorization Code Reuse Vulnerability: Early WarningEarly warning for a high-severity vulnerability in Gitea versions before 1.25.5 that may allow OAuth2 authorization code reuse.
EARLY WARNINGPYPIJULY 2026
fast-mcp-telegram Package Vulnerability: Bearer Token Path TraversalEarly warning on fast-mcp-telegram package vulnerability allowing path traversal to bypass Telegram session protection.
CONFIRMEDCARGOJULY 2026
Zebra <=v4.4.1: Critical Consensus Divergence Vulnerability ConfirmedZebra versions up to and including v4.4.1 have a critical consensus divergence vulnerability due to P2SH sigop undercount.
EARLY WARNINGGOJULY 2026
Rancher Manager Cluster Import Endpoint Vulnerable to Command InjectionEarly warning: Rancher Manager may allow command injection, risking Kubernetes cluster control.
EARLY WARNINGCARGOJULY 2026
SurrealDB Vulnerability Under InvestigationSurrealDB vulnerability reportedly allows authenticated users to bypass permission restrictions.
CONFIRMEDNPMJUNE 2026
Critical IBM Langflow OSS Vulnerability: Upgrade or Restrict Redis AccessConfirmed critical vulnerability in IBM Langflow OSS 1.0.0 to 1.10.0 allows Redis users to execute arbitrary code.
EARLY WARNINGWORDPRESSJUNE 2026
ProfileGrid WordPress Plugin Under Investigation for Critical VulnerabilityProfileGrid WordPress plugin reportedly vulnerable to privilege escalation via account takeover.
EARLY WARNINGGOJUNE 2026
Path Traversal Vulnerability in googleapis/mcp-toolbox HTTP ToolEarly warning of a path traversal vulnerability in googleapis/mcp-toolbox HTTP tool. Upgrade to version 1.3.0 or higher.
EARLY WARNINGNPMJUNE 2026
Gorse <0.5.10 Authentication Bypass VulnerabilityGorse <0.5.10 reportedly contains a critical authentication bypass vulnerability. Upgrade to 0.5.10 or later.
CONFIRMEDLINUXJUNE 2026
Linux Kernel 'pedit COW' Flaw CVE-2026-46331: Urgent Patch RequiredHigh-severity Linux kernel flaw CVE-2026-46331 allows local unprivileged users to gain root access. Patch now.
EARLY WARNINGGOJUNE 2026
golang.org/x/crypto: Potential Server Deadlock on Unexpected ResponsesEarly warning: golang.org/x/crypto may cause server deadlock on unexpected responses. Upgrade recommended.
EARLY WARNINGGOJUNE 2026
golang.org/x/crypto: Potential Server Deadlock VulnerabilityEarly warning of a potential vulnerability in golang.org/x/crypto that could lead to server deadlock.
EARLY WARNINGGOJUNE 2026
golang.org/x/crypto: Potential Server Deadlock VulnerabilityEarly warning of a potential vulnerability in golang.org/x/crypto that could cause server deadlock.
EARLY WARNINGGOJUNE 2026
golang.org/x/crypto Vulnerability: Monitor for Updatesgolang.org/x/crypto may have a vulnerability. Monitor for updates.
EARLY WARNINGGOJUNE 2026
golang.org/x/crypto Vulnerability: Potential Server DeadlockEarly warning of a potential vulnerability in golang.org/x/crypto that could cause server deadlock.
EARLY WARNINGGOJUNE 2026
golang.org/x/crypto Vulnerability: Early Warning and Mitigation StepsEarly warning for golang.org/x/crypto vulnerability. Learn about the potential risk and mitigation steps.
EARLY WARNINGNPMJUNE 2026
Budibase NoSQL Injection Vulnerability: Early Warning and Mitigation StepsEarly warning: Budibase has a NoSQL injection vulnerability. Learn how to assess your exposure and mitigate the risk.
CONFIRMEDGOJUNE 2026
Gogs Path Traversal Vulnerability: Critical RCE Threat ConfirmedGogs has a confirmed path traversal vulnerability leading to RCE. Upgrade now.
EARLY WARNINGGOJUNE 2026
Gogs Path Traversal Vulnerability: Potential Remote Code ExecutionEarly warning: Gogs has a path traversal vulnerability in organization names that may lead to remote code execution.
EARLY WARNINGGOJUNE 2026
Gogs Path Traversal Vulnerability: Critical RCE RiskEarly warning of a high-severity Gogs vulnerability that could lead to remote code execution.
CONFIRMEDGOJUNE 2026
Gogs Supply-Chain Threat: Multiple Vulnerabilities ConfirmedGogs package allows repo-write attackers to gain SSH footholds or RCE.
EARLY WARNINGGOJUNE 2026
Gogs Package Vulnerability: Potential Supply-Chain Attack RiskEarly warning of a Gogs package vulnerability that may allow symlink attacks.
EARLY WARNINGGOJUNE 2026
Gogs RCE Vulnerability via Pull Request Branch Name InjectionEarly warning: Gogs <0.15.0 reportedly allows RCE via pull request branch name injection.
EARLY WARNINGCISA_KEVJUNE 2026
Ubiquiti UniFi OS Vulnerability Under InvestigationReportedly, Ubiquiti UniFi OS has an improper input validation vulnerability allowing command injection.
EARLY WARNINGNPMJUNE 2026
Budibase Server Vulnerability: Arbitrary File Read via PWA Zip UploadEarly warning of a high-severity vulnerability in Budibase server allowing arbitrary file read.
CONFIRMEDCARGOJUNE 2026
Mise Package Vulnerability: Arbitrary Code Execution via Tera TemplatesMise package is vulnerable to arbitrary code execution through Tera templates in.tool-versions files.
EARLY WARNINGCARGOJUNE 2026
Mise Package Vulnerability: Arbitrary Code Execution via Tera TemplatesEarly warning: Mise package may allow arbitrary code execution via Tera templates in.tool-versions files.
EARLY WARNINGGOJUNE 2026
SiYuan Package Under Investigation for Remote Code ExecutionEarly warning: SiYuan package before v3.6.1 may allow remote code execution due to unsanitized metadata.
EARLY WARNINGPYPIJUNE 2026
Crawl4AI Authentication Bypass Vulnerability: Critical CVE AlertEarly warning of a critical authentication bypass vulnerability in Crawl4AI due to a hardcoded JWT key.
CONFIRMEDPYPIJUNE 2026
Langflow IDOR Vulnerability Confirmed: Upgrade and Review Access ControlsLangflow package has a confirmed IDOR vulnerability allowing access to other users' flows.
EARLY WARNINGPYPIJUNE 2026
Jupyter Server Vulnerability: Stored XSS via Missing Sandbox CSPEarly warning about a stored XSS vulnerability in Jupyter Server due to missing sandbox CSP. Upgrade to version 2.20.0 or later.
EARLY WARNINGPYPIJUNE 2026
praisonai-platform PyPI Package: Default JWT Secret VulnerabilityEarly warning: praisonai-platform PyPI package reportedly has a default JWT signing secret that enables token forgery.
EARLY WARNINGPYPIJUNE 2026
praisonai-platform PyPI Package: Potential Hardcoded JWT Secret IssueEarly warning: praisonai-platform <= 0.1.4 may use a hardcoded JWT secret, enabling unauthenticated access.
EARLY WARNINGCISA_KEVJUNE 2026
Splunk Enterprise Vulnerability Under Investigation: Early WarningSplunk Enterprise reportedly contains a vulnerability that could allow unauthorized file creation or truncation.
CONFIRMEDGEMJUNE 2026
Avo Gem Critical Vulnerability: Missing Authorization Flaw ConfirmedAvo gem has a critical missing authorization flaw allowing privilege escalation and cross-tenant data exposure.
CONFIRMEDPYPIJUNE 2026
picklescan PyPI Package Unsafe Deserialization Vulnerability Confirmedpicklescan versions before 1.0.1 contain a high severity unsafe deserialization vulnerability allowing arbitrary code execution.
CONFIRMEDPYPIJUNE 2026
picklescan PyPI Package <= 0.0.32 Vulnerable: Upgrade Nowpicklescan package <= 0.0.32 has an arbitrary file writing vulnerability. Upgrade to 0.0.33 or later.
EARLY WARNINGGOJUNE 2026
rclone Package Vulnerability: Unauthenticated Command ExecutionEarly warning of a high severity vulnerability in rclone package allowing unauthenticated command execution.
EARLY WARNINGPYPIJUNE 2026
Multiple Vulnerabilities Reported in Crawl4AI Docker API ServerReportedly multiple critical vulnerabilities affect Crawl4AI Docker API server endpoints.
CONFIRMEDPYPIJUNE 2026
Critical Vulnerability in Crawl4AI Package: Sandbox Escape and RCEConfirmed critical vulnerability in Crawl4AI package allows sandbox escape and remote code execution.
EARLY WARNINGPYPIJUNE 2026
Crawl4AI Package Vulnerability: AST Sandbox Escape ThreatEarly warning on a potential vulnerability in the Crawl4AI package allowing sandbox escape and arbitrary code execution.
EARLY WARNINGPIPJUNE 2026
Potential Auth Bypass in vLLM Affecting OpenAI APIReportedly, a vulnerability in vLLM allows bypassing OpenAI API authentication. Upgrade to v0.14.1 or later.
EARLY WARNINGPYPIJUNE 2026
vLLM: Potential Authentication Bypass Vulnerability in ASGI Web ServersEarly warning of a potential authentication bypass vulnerability in vLLM affecting ASGI web servers.
EARLY WARNINGPHPJUNE 2026
LiteSpeed cPanel Plugin Flaw: Early Warning of Exploited VulnerabilityCISA warns of an actively exploited flaw in LiteSpeed cPanel Plugin, urging immediate action for affected users.
EARLY WARNINGNPMJUNE 2026
YouTransfer npm Package Issue: Arbitrary Code Execution RiskEarly warning of a vulnerability in YouTransfer npm package allowing arbitrary code execution.
EARLY WARNINGPACKAGISTJUNE 2026
Firefly III v6.5.9 Access Control Issue: Early WarningEarly warning of a critical access control issue in Firefly III v6.5.9 webhook management.
EARLY WARNINGPACKAGISTJUNE 2026
shlink <= 5.0.1 SSRF Vulnerability: Early WarningEarly warning of a Server-Side Request Forgery vulnerability in shlink <= 5.0.1.
EARLY WARNINGMAVENJUNE 2026
SNMP4J-Agent 3.8.3 Vulnerability: Arbitrary Code Execution RiskEarly warning of a high-severity vulnerability in SNMP4J-Agent 3.8.3 that may allow remote code execution.
CONFIRMEDNPMJUNE 2026
remotion npm Package Arbitrary File Write Vulnerability Confirmedremotion npm package version v4.0.409 has an arbitrary file write vulnerability. Upgrade and review environments.
EARLY WARNINGNPMJUNE 2026
Vitest Browser Mode API Exposure: Potential RCE VulnerabilityEarly warning of a potential remote code execution vulnerability in Vitest Browser Mode API.
EARLY WARNINGPYPIJUNE 2026
ChromaDB Code Injection Vulnerability: Early WarningEarly warning for a code injection vulnerability in ChromaDB Python package versions 0.4.17 and later.
EARLY WARNINGMAVENJUNE 2026
Apache CXF JNDI Injection Vulnerability: Early WarningEarly warning for Apache CXF JNDI Injection Vulnerability. Assess your exposure now.
EARLY WARNINGMAVENJUNE 2026
Apache CXF JNDI Injection Vulnerability: Critical CVE AlertEarly warning of a critical JNDI Injection vulnerability in Apache CXF's JCA integration module. Upgrade to versions 4.2.2 or 4.1.7.
EARLY WARNINGMAVENJUNE 2026
Apache CXF OAuth2 JWT Audience Validation Issue: Early WarningEarly warning of a high severity issue in Apache CXF OAuth2 JWT Audience Validation. Upgrade to versions 4.2.2 or 4.1.7.
EARLY WARNINGPYPIJUNE 2026
meta-ads-mcp PyPI Package Vulnerability: Critical CVE AlertEarly warning: meta-ads-mcp PyPI package vulnerability allows unauthenticated HTTP requests to leak Meta Access Tokens.
EARLY WARNINGGOJUNE 2026
Openshift Migration Advisor Vulnerability: Critical Data Deletion RiskEarly warning of a vulnerability in Openshift Migration Advisor that allows authenticated users to delete all customer data.
EARLY WARNINGGOJUNE 2026
migration-planner Package Vulnerability: Broken Access ControlEarly warning of a broken access control vulnerability in migration-planner package.
EARLY WARNINGGOJUNE 2026
Openshift Migration Advisor Agent-API Flaw: Early WarningEarly warning of a flaw in Openshift Migration Advisor agent-API that could allow cross-tenant data manipulation.
EARLY WARNINGGOJUNE 2026
migration-planner Vulnerability: Improper Input Sanitization RiskEarly warning of a high severity vulnerability in migration-planner due to improper input sanitization.
EARLY WARNINGGOJUNE 2026
Assisted Migration Agent Vulnerability: Insecure TLS ConnectionsEarly warning of a vulnerability in assisted-migration-agent that uses insecure TLS connections.
EARLY WARNINGGOJUNE 2026
Assisted-migration-agent Vulnerability: Path Traversal Threat AlertEarly warning of a path traversal vulnerability in assisted-migration-agent that could allow arbitrary file write and remote code execution.
CONFIRMEDNPMJUNE 2026
V8 npm Package Vulnerability CVE-2026-11645: Update Chrome NowHigh-severity V8 npm package vulnerability CVE-2026-11645 is being actively exploited. Update Chrome to 149.0.7827.103 or later.
EARLY WARNINGCOMPOSERJUNE 2026
PHPSpreadsheet Patch Bypass Under InvestigationReportedly, PHPSpreadsheet has a bypass for CVE-2026-34084 patch, enabling remote code execution.
CONFIRMEDPYPIJUNE 2026
Microsoft durabletask PyPI Package Compromised: Critical Supply Chain ThreatThree malicious versions of Microsoft's durabletask Python SDK were published to PyPI, stealing credentials and spreading laterally.
EARLY WARNINGMAVENJUNE 2026
Apache Fory Java SDK Deserialization VulnerabilityReported deserialization flaw in Apache Fory Java SDK may allow bypass of security checks.
CONFIRMEDPYPIJUNE 2026
Jupyter Enterprise Gateway SSTI Vulnerability: Critical Threat ConfirmedConfirmed high severity threat in Jupyter Enterprise Gateway allows remote code execution via SSTI.
EARLY WARNINGGOMAY 2026
KubeVirt virt-handler Vulnerability Under InvestigationA flaw in KubeVirt's virt-handler component is under investigation. Users with edit permissions may be at risk.
EARLY WARNINGPYPIMAY 2026
MLflow <=3.10.1.dev0 Vulnerability: Unauthorized Access RiskMLflow <=3.10.1.dev0 may allow unauthorized access to multipart upload endpoints.
EARLY WARNINGGOMAY 2026
MCP Gateway: Potential Authority Injection and JWT BypassEarly warning: MCP Gateway may allow authority injection and JWT bypass via unauthenticated path.
EARLY WARNINGCOMPOSERMAY 2026
TYPO3 'Content Element Selector' Extension Under Investigation for RCETYPO3 'Content Element Selector' extension is reportedly vulnerable to Remote Code Execution via PHP Object Injection.
EARLY WARNINGGOMAY 2026
Crabbox Prior to v0.12.0: Environment Variable Exposure VulnerabilityEarly warning: Crabbox prior to v0.12.0 may expose local secrets via environment variables.
EARLY WARNINGGOMAY 2026
Portainer Endpoint Security Bypass Under InvestigationPortainer has an endpoint security bypass via Swarm service create/update. Review configurations.
EARLY WARNINGNPMMAY 2026
n8n npm Package Vulnerability: XML Node Patch Bypass Under InvestigationEarly warning: n8n npm package may have a critical vulnerability allowing RCE. Upgrade to mitigate.
EARLY WARNINGNPMMAY 2026
n8n npm Package Vulnerability: Potential Remote Code ExecutionEarly warning: n8n npm package has a vulnerability that could lead to remote code execution.
EARLY WARNINGNPMMAY 2026
Flowise npm Package RCE Vulnerability Under InvestigationFlowise npm package reportedly allows authenticated RCE via NodeVM sandbox escape.
EARLY WARNINGMAVENMAY 2026
Apache Tomcat HTTP/2 Header Validation Issue: Early WarningEarly warning for Apache Tomcat HTTP/2 header validation issue. Check your versions and upgrade if necessary.
EARLY WARNINGNPMMAY 2026
SandboxJS npm Package Sandbox Escape VulnerabilitySandboxJS npm package reportedly has a sandbox escape vulnerability due to Function.caller leakage.
EARLY WARNINGPYPIMAY 2026
High Severity: dash-uploader Path Traversal VulnerabilityEarly warning of a high severity path traversal vulnerability in dash-uploader versions 0.1.0 through 0.7.0a2.
EARLY WARNINGPYPIMAY 2026
PyTorch Lightning PyPI Package CompromisedReportedly, PyTorch Lightning PyPI package versions 2.6.2 and 2.6.3 have been compromised. Assess your exposure now.
EARLY WARNINGGOMAY 2026
Pelican Web UI Privilege Escalation Vulnerability: Early WarningEarly warning of a privilege escalation vulnerability in Pelican Web UI. Assess your exposure and take action.
EARLY WARNINGMAVENMAY 2026
Apache OpenNLP ExtensionLoader Vulnerability: Critical CVE AlertEarly warning of a critical vulnerability in Apache OpenNLP ExtensionLoader. Learn about the risk and recommended actions.
EARLY WARNINGMAVENMAY 2026
Apache Polaris Improper Input Validation Issue: Early WarningEarly warning of an improper input validation issue in Apache Polaris. Assess your exposure and take recommended actions.
EARLY WARNINGMAVENMAY 2026
Apache OpenNLP ExtensionLoader Vulnerability: Critical CVE AlertEarly warning of a critical vulnerability in Apache OpenNLP ExtensionLoader. Assess your exposure now.
EARLY WARNINGMAVENAPRIL 2026
Jenkins GitHub Plugin XSS Vulnerability: Critical CVE-2026-42523Early warning: Jenkins GitHub Plugin versions 1.46.0 and earlier have a stored XSS vulnerability.
EARLY WARNINGMAVENAPRIL 2026
Apache Camel Components Vulnerable to Unsafe DeserializationEarly warning of a high severity vulnerability in Apache Camel components.
EARLY WARNINGNPMAPRIL 2026
Fastify Header Stripping Vulnerability Under InvestigationFastify's connection header abuse may enable stripping of proxy-added headers, affecting @fastify/reply-from and @fastify/http-proxy users.
EARLY WARNINGGOAPRIL 2026
OAuth2 Proxy Authentication Bypass: Early WarningOAuth2 Proxy has an authentication bypass vulnerability via X-Forwarded-Uri header spoofing.
EARLY WARNINGMAVENMARCH 2026
OpenTelemetry Java Agent: Unsafe Deserialization Vulnerability ReportedEarly warning: OpenTelemetry Java agent versions prior to 2.26.1 may have an unsafe deserialization vulnerability.
EARLY WARNINGNPMMARCH 2026
jsrsasign Package Vulnerability: Incomplete Comparison Threatjsrsasign versions from 7.0.0 to before 11.1.1 may allow private key recovery.
EARLY WARNINGMAVENMARCH 2026
Spinnaker Clouddriver and Orca URL Validation Bypass VulnerabilityEarly warning of a critical vulnerability in Spinnaker's clouddriver and orca components.
EARLY WARNINGPYPIFEBRUARY 2026
Critical Vulnerability in NLTK Downloader ComponentA critical vulnerability in NLTK downloader may allow arbitrary code execution. Upgrade to a patched version as soon as available.
EARLY WARNINGGOFEBRUARY 2026
Alist Application Vulnerable to MitM AttacksAlist application reportedly disables TLS verification by default, exposing it to MitM attacks.
EARLY WARNINGGOJANUARY 2026
Potential Scope Validation Bypass in Free5gc NRF 1.4.0An issue in Free5gc NRF 1.4.0 may allow scope validation bypass. Upgrade or patch.
EARLY WARNINGPYPIJANUARY 2026
Crawl4AI Docker API Vulnerable to Remote Code ExecutionReportedly, a critical remote code execution vulnerability exists in Crawl4AI Docker API. Upgrade to v0.8.0 or disable the API.
EARLY WARNINGPYPIDECEMBER 2025
Apache Airflow Providers Edge3 RCE VulnerabilityReportedly, Apache Airflow Providers Edge3 exposes an internal API allowing RCE. Assess your exposure now.
EARLY WARNINGMAVENSEPTEMBER 2025
Apache IoTDB Deserialization Vulnerability Under InvestigationApache IoTDB may have a high-severity deserialization flaw. Upgrade to 2.0.5 or restrict exposure.
EARLY WARNINGMAVENSEPTEMBER 2025
jinjava Sandbox Bypass via JavaType-Based Deserialization: Early WarningEarly warning of a potential sandbox bypass vulnerability in jinjava via JavaType-based deserialization.
EARLY WARNINGPYPIAUGUST 2025
ExecuTorch Integer Overflow Vulnerability: Early Warning for UsersEarly warning for ExecuTorch users about a critical integer overflow vulnerability. Assess your exposure and take action now.
EARLY WARNINGPYPIAUGUST 2025
ExecuTorch Integer Overflow Vulnerability: Early Warning IssuedExecuTorch versions prior to commit 0830af8207240df8d7f35b984cdf8bc35d74fa73 have a critical integer overflow vulnerability.
EARLY WARNINGPYPIAUGUST 2025
ExecuTorch Heap Buffer Overflow Vulnerability: Early WarningExecuTorch heap buffer overflow vulnerability under investigation. Assess your exposure now.
EARLY WARNINGPYPIAUGUST 2025
ExecuTorch Vulnerability: Heap-based Buffer Overflow RiskExecuTorch versions prior to commit cea9b23aa8ff78aff92829a466da97461cc7930c are reportedly vulnerable to heap-based buffer overflows.
EARLY WARNINGPYPIAUGUST 2025
ExecuTorch Vulnerability: Out-of-Bounds Access Threat AlertExecuTorch out-of-bounds access vulnerability under investigation. Upgrade to commit fb03b6f85596a8f954d97929075335255b6a58d4 or later.
EARLY WARNINGPYPIJUNE 2025
llama_index v0.12.21 Vulnerable to SQL Injection: Early WarningEarly warning: llama_index v0.12.21 has SQL injection vulnerabilities. Upgrade and review SQL usage.
EARLY WARNINGCARGOAPRIL 2025
SurrealDB Command-Line Tool Vulnerability: SurrealQL Injection RiskEarly warning of a SurrealDB command-line tool vulnerability that may allow SurrealQL injection.
EARLY WARNINGMAVENAPRIL 2025
Apache Pinot Authentication Bypass Vulnerability: Early WarningApache Pinot is under investigation for an authentication bypass issue. Upgrade to the latest version.
EARLY WARNINGPYPIMARCH 2025
Potential SQL Injection in DuckDBRetriever: What You Need to KnowEarly warning: SQL injection vulnerability in DuckDBRetriever may allow RCE.
EARLY WARNINGMAVENJANUARY 2025
Apache Ranger UI SSRF Vulnerability: Early Warning and MitigationEarly warning of a critical SSRF vulnerability in Apache Ranger UI. Learn how to assess your exposure and mitigate the risk.
EARLY WARNINGMAVENSEPTEMBER 2024
hermes-management RCE Vulnerability Due to Apache commons-jxpathEarly warning of a remote code execution vulnerability in hermes-management due to Apache commons-jxpath.