| CVE-2026-19693 | |
| Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') | |
| CVE-2026-82299 | |
| Resource Exhaustion | |
| CVE-2026-82298 | |
| CVE-2026-78596 | |
| GHSA-2x7j-588g-ccc2 | |
| GHSA-8m3c-c648-2xjj | |
| CVE-2026-82302 | |
| Link Following | |
| CVE-2026-78583 | |
| Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') | |
| CVE-2026-78593 | |
| GHSA-wmmp-3585-3rmp | |
| CVE-2026-82293 | |
| CVE-2026-78591 | |
| CVE-2026-78598 | |
| CVE-2026-78599 | |
| CVE-2026-78586 | |
| CVE-2026-78590 | |
| CVE-2026-78608 | |
| CVE-2026-75975 | |
| CVE-2026-78592 | |
| CVE-2026-78603 | |
| CVE-2026-72628 | |
| CVE-2026-33465 | |
| CVE-2026-72652 | |
| CVE-2026-72654 | |
| CVE-2026-76172 | |
| CVE-2026-78597 | |
| Integer Overflow or Wraparound | |
| CVE-2026-8657 | |
| CVE-2026-45822 | |
| CVE-2026-72650 | |
| CVE-2026-72664 | |
| CVE-2026-72670 | |
| CVE-2026-72660 | |
| CVE-2026-72673 | |
| CVE-2026-72671 | |
| CVE-2026-72669 | |
| CVE-2026-72658 | |
| CVE-2026-72677 | |
| CVE-2026-72651 | |
| CVE-2026-72675 | |
| CVE-2026-72659 | |
| CVE-2026-72663 | |
| CVE-2026-49089 | |
| CVE-2026-72653 | |
| CVE-2026-72667 | |
| CVE-2026-49096 | |
| CVE-2026-72655 | |
| CVE-2026-72661 | |
| CVE-2026-72665 | |
| CVE-2026-72630 | |
| CVE-2026-72632 | |
| CVE-2026-72629 | |
| CVE-2026-56876 | |
| CVE-2026-63142 | |
| CVE-2026-63143 | |
| CVE-2026-13149 | |
| Interpretation Conflict | |
| CVE-2026-16728 | |
| Server-Side Request Forgery (SSRF) | |
| Information Exposure | |
| OS Command Injection | |
| CVE-2026-18446 | |
| GHSA-42h9-826w-cgv3 | |
| Information Exposure | |
| CVE-2026-49095 | |
| CVE-2026-56151 | |
| OS Command Injection | |
| CVE-2026-63145 | |
| CVE-2025-9910 | |
| Arbitrary Code Injection | |
| Loop with Unreachable Exit Condition ('Infinite Loop') | |
| CVE-2026-33463 | |
| Cleartext Transmission of Sensitive Information | |
| Algorithmic Complexity | |
| GHSA-mmx7-hfxf-jppx | |
| GHSA-wqvq-jvpq-h66f | |
| Uncontrolled Recursion | |
| CVE-2026-42399 | |
| Information Exposure | |
| Uncaught Exception | |
| CVE-2026-6733 | |
| CVE-2026-49087 | |
| Algorithmic Complexity | |
| Uncaught Exception | |
| GHSA-r292-9mhp-454m | |
| CVE-2026-39244 | |
| Resource Exhaustion | |
| Improper Verification of Cryptographic Signature | |
| CVE-2025-12816 | |
| Cross-site Scripting (XSS) | |
| Algorithmic Complexity | |
| Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') | |
| Allocation of Resources Without Limits or Throttling | |
| Loop with Unreachable Exit Condition ('Infinite Loop') | |
| Improper Input Validation | |
| Deserialization of Untrusted Data | |
| Directory Traversal | |
| CVE-2026-12143 | |
| CVE-2026-33464 | |
| Uncontrolled Recursion | |
| Use of Uninitialized Resource | |
| Resource Exhaustion | |
| Improper Check or Handling of Exceptional Conditions | |
| GHSA-7q8q-rj6j-mhjq | |
| Uncontrolled Recursion | |
| Inefficient Regular Expression Complexity | |
| CVE-2025-13204 | |
| CVE-2025-48985 | |
| CVE-2026-63261 | |
| GHSA-268h-hp4c-crq3 | |
| Improper Validation of Syntactic Correctness of Input | |
| GHSA-pmv8-rq9r-6j72 | |
| Loop with Unreachable Exit Condition ('Infinite Loop') | |
| Arbitrary Code Injection | |
| CVE-2026-63141 | |
| CVE-2026-42400 | |
| Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') | |
| CVE-2026-11525 | |
| CVE-2026-13676 | |
| Uncontrolled Recursion | |
| GHSA-5p4m-2wfm-xmqj | |
| Resource Exhaustion | |
| CVE-2026-15157 | |
| CVE-2026-42401 | |
| CVE-2026-56147 | |
| CVE-2026-9679 | |
| CVE-2026-14257 | |
| CVE-2026-16729 | |
| CVE-2026-63139 | |
| Incorrect Type Conversion or Cast | |
| CVE-2026-16221 | |
| GHSA-r7g4-qg5f-qqm2 | |
| CVE-2026-63260 | |
| Integer Overflow or Wraparound | |
| GHSA-jqh4-m9w3-8hp9 | |
| Uncaught Exception | |
| Allocation of Resources Without Limits or Throttling | |
| Uncaught Exception | |
| CVE-2026-33462 | |
| Uncaught Exception | |
| Resource Exhaustion | |
| GHSA-p6gq-j5cr-w38f | |
| CVE-2026-12151 | |
| Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') | |
| CVE-2026-42398 | |
| Interpretation Conflict | |
| Unintended Proxy or Intermediary ('Confused Deputy') | |
| Allocation of Resources Without Limits or Throttling | |
| Resource Exhaustion | |
| CVE-2026-26939 | |
| CVE-2026-33459 | |
| CVE-2026-33461 | |
| Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') | |
| Improper Handling of Unicode Encoding | |
| Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') | |
| Cross-site Scripting (XSS) | |
| Improper Handling of Exceptional Conditions | |
| Arbitrary Code Injection | |
| Improper Input Validation | |
| CVE-2026-6322 | |
| OS Command Injection | |
| Deserialization of Untrusted Data | |
| CVE-2026-6321 | |
| Resource Exhaustion | |
| Uncontrolled Recursion | |
| Arbitrary Code Injection | |
| Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') | |
| Improper Encoding or Escaping of Output | |
| Allocation of Resources Without Limits or Throttling | |
| HTTP Response Splitting | |
| Server-Side Request Forgery (SSRF) | |
| Improper Authentication | |
| Allocation of Resources Without Limits or Throttling | |
| Uncontrolled Recursion | |
| Improperly Controlled Modification of Dynamically-Determined Object Attributes | |
| Permissive Whitelist | |
| CRLF Injection | |
| Permissive Whitelist | |
| Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') | |
| Improper Validation of Specified Quantity in Input | |
| Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion') | |
| CVE-2026-26940 | |
| Uncontrolled Recursion | |
| Loop with Unreachable Exit Condition ('Infinite Loop') | |
| GHSA-c7w3-x93f-qmm8 | |
| Cross-site Scripting (XSS) | |
| Improper Certificate Validation | |
| Improper Input Validation | |
| Inefficient Regular Expression Complexity | |
| Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') | |
| Improper Verification of Cryptographic Signature | |
| Resource Exhaustion | |
| Arbitrary Code Injection | |
| Improper Check for Unusual or Exceptional Conditions | |
| Cross-site Scripting (XSS) | |
| GHSA-442j-39wm-28r2 | |
| GHSA-7rx3-28cr-v5wh | |
| Arbitrary Code Injection | |
| Arbitrary Code Injection | |
| CVE-2026-2950 | |
| CVE-2026-4800 | |
| Inefficient Regular Expression Complexity | |
| Arbitrary Code Injection | |
| Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') | |
| GHSA-r4q5-vmmm-2653 | |
| HTTP Response Splitting | |
| Unintended Proxy or Intermediary ('Confused Deputy') | |
| GHSA-6v7q-wjvx-w8wg | |
| Information Exposure | |
| Resource Exhaustion | |
| GHSA-vvjj-xcjg-gr5g | |
| Out-of-bounds Write | |
| XML Injection | |
| CVE-2026-1527 | |
| CVE-2026-1526 | |
| CVE-2026-26934 | |
| Directory Traversal | |
| CVE-2026-26936 | |
| CVE-2026-1525 | |
| CVE-2026-26937 | |
| Directory Traversal | |
| CVE-2026-2229 | |
| CVE-2026-26935 | |
| CVE-2026-3449 | |
| CVE-2026-1528 | |
| CVE-2025-68389 | |
| Directory Traversal | |
| Algorithmic Complexity | |
| CVE-2025-68387 | |
| Inefficient Regular Expression Complexity | |
| CVE-2026-0530 | |
| CVE-2025-68422 | |
| Allocation of Resources Without Limits or Throttling | |
| Server-Side Request Forgery (SSRF) | |
| CVE-2026-0531 | |
| CVE-2025-37732 | |
| CVE-2026-0532 | |
| Buffer Overflow | |
| CVE-2025-68385 | |
| CVE-2025-68386 | |
| CVE-2025-25009 | |
| CVE-2025-37728 | |
| CVE-2025-25018 | |
| CVE-2025-25017 | |
| OS Command Injection | |
| Inefficient Regular Expression Complexity | |
| Directory Traversal | |
| Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion') | |
| Inefficient Regular Expression Complexity | |
| Incorrect Regular Expression | |
| OS Command Injection | |
| CVE-2026-2739 | |
| Server-Side Request Forgery (SSRF) | |
| CVE-2026-2327 | |
| Improper Check for Unusual or Exceptional Conditions | |
| Directory Traversal | |
| CVE-2025-13465 | |
| Improper Handling of Unicode Encoding | |
| GHSA-6475-r3vj-m8vf | |
| Allocation of Resources Without Limits or Throttling | |
| Directory Traversal | |