| Race Condition | |
| CVE-2026-13676 | |
| Use of Less Trusted Source | |
| Cross-site Scripting (XSS) | |
| Cross-site Scripting (XSS) | |
| Authorization Bypass Through User-Controlled Key | |
| GHSA-vhf8-cg2h-cg3p | |
| Cleartext Storage of Sensitive Information | |
| Improper Privilege Management | |
| Expression Language Injection | |
| OS Command Injection | |
| GHSA-9cmh-xcqm-5hqr | |
| GHSA-xmc9-4f2h-jf9c | |
| Time-of-check Time-of-use (TOCTOU) | |
| GHSA-64xh-79j6-r5v8 | |
| Cross-site Scripting (XSS) | |
| GHSA-652q-gvq3-74qv | |
| GHSA-jqwr-vx3p-r266 | |
| GHSA-6qc9-mqvw-jg7x | |
| GHSA-8342-988q-86cr | |
| GHSA-gv7g-jm28-cr3m | |
| Server-Side Request Forgery (SSRF) | |
| GHSA-gf29-4f56-r2jf | |
| Authorization Bypass Through User-Controlled Key | |
| GHSA-rcv6-pvrj-4xcg | |
| GHSA-cj9h-qx8g-pq2g | |
| GHSA-pf2q-pxhf-hgmw | |
| GHSA-hx4h-vr3m-45vh | |
| GHSA-xwx6-jjhv-84p8 | |
| Incorrect Authorization | |
| Information Exposure Through Log Files | |
| Incorrect Authorization | |
| GHSA-2x35-3fw4-9jr4 | |
| Incorrect Authorization | |
| Missing Authentication for Critical Function | |
| Allocation of Resources Without Limits or Throttling | |
| CVE-2026-6733 | |
| Uncaught Exception | |
| CVE-2026-9679 | |
| CVE-2026-11525 | |
| GHSA-hcpx-6fm6-wx23 | |
| GHSA-42h9-826w-cgv3 | |
| GHSA-pmv8-rq9r-6j72 | |
| GHSA-xj6q-8x83-jv6g | |
| GHSA-7q8q-rj6j-mhjq | |
| GHSA-mmx7-hfxf-jppx | |
| GHSA-gcfj-64vw-6mp9 | |
| GHSA-f4gw-2p7v-4548 | |
| GHSA-mwf2-3pr3-8698 | |
| GHSA-jqh4-m9w3-8hp9 | |
| Authorization Bypass Through User-Controlled Key | |
| Allocation of Resources Without Limits or Throttling | |
| Information Exposure | |
| Inefficient Regular Expression Complexity | |
| Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') | |
| Protection Mechanism Failure | |
| Improper Authentication | |
| Incorrect Authorization | |
| Authorization Bypass Through User-Controlled Key | |
| SQL Injection | |
| Incorrect Authorization | |
| Incorrect Authorization | |
| Incomplete Blacklist | |
| CVE-2026-5038 | |
| Improper Input Validation | |
| Uncontrolled Recursion | |
| Allocation of Resources Without Limits or Throttling | |
| Algorithmic Complexity | |
| CVE-2026-9678 | |
| SQL Injection | |
| Authorization Bypass Through User-Controlled Key | |
| Use of Less Trusted Source | |
| Improper Encoding or Escaping of Output | |
| CVE-2026-6734 | |
| GHSA-268h-hp4c-crq3 | |
| GHSA-r7g4-qg5f-qqm2 | |
| Interpretation Conflict | |
| Directory Traversal | |
| Insufficient Verification of Data Authenticity | |
| GHSA-wqvq-jvpq-h66f | |
| CVE-2026-12151 | |
| GHSA-p6gq-j5cr-w38f | |
| CRLF Injection | |
| CVE-2026-5079 | |
| CVE-2026-9697 | |
| CVE-2026-12143 | |
| Overly Permissive Cross-domain Whitelist | |
| Uncontrolled Recursion | |
| Improper Input Validation | |
| GHSA-664h-gpgq-h6xx | |
| CVE-2026-9277 | |
| Incorrect Authorization | |
| GHSA-h3jj-5f3v-3685 | |
| Exposure of Data Element to Wrong Session | |
| Information Exposure | |
| GHSA-hv7x-3x78-gx53 | |
| Directory Traversal | |
| GHSA-jwm3-qcfw-c5pp | |
| Uncaught Exception | |
| Uncaught Exception | |
| Cross-site Scripting (XSS) | |
| Resource Exhaustion | |
| Missing Authentication for Critical Function | |
| Improper Handling of Highly Compressed Data (Data Amplification) | |
| Improper Input Validation | |
| Information Exposure | |
| Cross-site Scripting (XSS) | |
| Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') | |
| Cross-site Scripting (XSS) | |
| SQL Injection | |
| SQL Injection | |
| Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') | |
| Authentication Bypass | |
| Improper Authorization | |
| HTTP Request Smuggling | |
| Incorrect Regular Expression | |
| HTTP Response Splitting | |
| CVE-2026-8723 | |
| CVE-2026-3449 | |
| Cross-site Scripting (XSS) | |
| Loop with Unreachable Exit Condition ('Infinite Loop') | |
| GHSA-c7w3-x93f-qmm8 | |
| Out-of-bounds Write | |
| Directory Traversal | |
| GHSA-vvjj-xcjg-gr5g | |
| Improper Control of Dynamically-Managed Code Resources | |
| Improper Control of Dynamically-Managed Code Resources | |
| Arbitrary Argument Injection | |
| Exposure of Resource to Wrong Sphere | |
| Improper Control of Dynamically-Managed Code Resources | |
| Resource Exhaustion | |
| Improper Control of Dynamically-Managed Code Resources | |
| Protection Mechanism Failure | |
| Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') | |
| Resource Exhaustion | |
| XML Injection | |
| Improper Handling of Exceptional Conditions | |
| Arbitrary Code Injection | |
| Deserialization of Untrusted Data | |
| Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') | |
| Improper Input Validation | |
| Uncontrolled Recursion | |
| Improper Handling of Unicode Encoding | |
| Uncontrolled Recursion | |
| Arbitrary Code Injection | |
| Protection Mechanism Failure | |
| GHSA-q3fm-4wcw-g57x | |
| Protection Mechanism Failure | |
| Exposure of Resource to Wrong Sphere | |
| Cross-site Scripting (XSS) | |
| Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') | |
| Protection Mechanism Failure | |
| Use of Uninitialized Resource | |
| Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') | |