| Out-of-bounds Write | |
| NULL Pointer Dereference | |
| Allocation of Resources Without Limits or Throttling | |
| Loop with Unreachable Exit Condition ('Infinite Loop') | |
| Link Following | |
| Double Free | |
| CVE-2026-42501 | |
| CVE-2026-39825 | |
| CVE-2026-42499 | |
| Cross-site Scripting (XSS) | |
| Improper Encoding or Escaping of Output | |
| Resource Exhaustion | |
| GHSA-fw8g-cg8f-9j28 | |
| Information Exposure | |
| Cross-site Scripting (XSS) | |
| GHSA-xmrv-pmrh-hhx2 | |
| CVE-2026-33816 | |
| SQL Injection | |
| Allocation of Resources Without Limits or Throttling | |
| Access of Resource Using Incompatible Type ('Type Confusion') | |
| CVE-2026-27143 | |
| Improper Certificate Validation | |
| Allocation of Resources Without Limits or Throttling | |
| Link Following | |
| Incorrect Authorization | |
| Cross-site Scripting (XSS) | |
| Allocation of Resources Without Limits or Throttling | |
| CVE-2026-32280 | |
| Improper Certificate Validation | |
| Uncontrolled Memory Allocation | |
| Untrusted Search Path | |
| Uncaught Exception | |
| Improper Authorization | |
| Improper Certificate Validation | |
| Improper Certificate Validation | |
| Directory Traversal | |
| Cross-site Scripting (XSS) | |
| Direct Request ('Forced Browsing') | |
| Untrusted Search Path | |
| Improper Initialization | |
| CVE-2025-68121 | |
| CVE-2025-61732 | |
| Allocation of Resources Without Limits or Throttling | |
| Allocation of Resources Without Limits or Throttling | |
| Out-of-bounds Write | |
| CVE-2025-61731 | |
| CVE-2025-61730 | |
| Allocation of Resources Without Limits or Throttling | |
| Improper Certificate Validation | |
| Improper Certificate Validation | |
| CVE-2025-47914 | |
| CVE-2025-58181 | |