| CVE-2026-46680 | |
| Missing Authorization | |
| Resource Exhaustion | |
| Out-of-Bounds | |
| CVE-2026-46598 | |
| Improper Certificate Validation | |
| Incorrect Type Conversion or Cast | |
| Improper Verification of Cryptographic Signature | |
| Improper Restriction of Rendered UI Layers or Frames | |
| CVE-2026-39821 | |
| Missing Authorization | |
| CVE-2026-46595 | |
| Improper Certificate Validation | |
| Deserialization of Untrusted Data | |
| Improper Enforcement of Message Integrity During Transmission in a Communication Channel | |
| Improper Restriction of Rendered UI Layers or Frames | |
| Cross-site Scripting (XSS) | |
| Integer Overflow or Wraparound | |
| Improper Restriction of Rendered UI Layers or Frames | |
| CVE-2026-39824 | |
| Improper Certificate Validation | |
| CVE-2026-42507 | |
| CVE-2026-27145 | |
| CVE-2026-42504 | |
| GHSA-w5pp-99ch-qj29 | |
| Directory Traversal | |
| Improper Encoding or Escaping of Output | |
| Directory Traversal | |
| GHSA-pmwq-pjrm-6p5r | |
| Uncontrolled Recursion | |
| Incorrect Behavior Order: Validate Before Canonicalize | |
| Cross-site Scripting (XSS) | |
| CVE-2026-42499 | |
| CVE-2026-42501 | |
| Out-of-bounds Write | |
| Improper Encoding or Escaping of Output | |
| Loop with Unreachable Exit Condition ('Infinite Loop') | |
| NULL Pointer Dereference | |
| Double Free | |
| Allocation of Resources Without Limits or Throttling | |
| Link Following | |
| CVE-2026-39825 | |
| Off-by-one Error | |
| Authentication Bypass | |
| Allocation of Resources Without Limits or Throttling | |
| Access of Resource Using Incompatible Type ('Type Confusion') | |
| GHSA-3xc5-wrhm-f963 | |
| CVE-2026-27143 | |
| Incorrect Authorization | |
| Link Following | |
| Allocation of Resources Without Limits or Throttling | |
| Improper Certificate Validation | |
| Allocation of Resources Without Limits or Throttling | |
| Improper Certificate Validation | |
| CVE-2026-32280 | |
| Cross-site Scripting (XSS) | |
| Untrusted Search Path | |
| Uncaught Exception | |
| Integer Underflow | |
| Improper Validation of Array Index | |
| Directory Traversal | |
| Directory Traversal | |
| GHSA-q382-vc8q-7jhj | |
| Cross-site Request Forgery (CSRF) | |
| Improper Authorization | |
| Directory Traversal | |
| Cross-site Scripting (XSS) | |
| Improper Certificate Validation | |
| Direct Request ('Forced Browsing') | |
| Improper Certificate Validation | |
| Untrusted Search Path | |
| CVE-2026-1229 | |
| CVE-2026-26014 | |
| Improper Validation of Integrity Check Value | |
| Incorrect Execution-Assigned Permissions | |
| CVE-2025-47914 | |
| Memory Leak | |
| CVE-2025-58181 | |