|
1681
|
9.8 |
CRITICAL
Network
|
-
|
-
|
ProxySQL is a proxy for MySQL and its forks, as well as PostgreSQL. Versions 2.0.18 through 3.0.8 have a pre-authentication heap memory corruption vulnerability in the MySQL and PostgreSQL protocol f…
|
CWE-787
Out-of-bounds Write
|
CVE-2026-48773
|
2026-06-24 00:55 |
2026-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1682
|
- |
|
-
|
-
|
node-tar is a full-featured Tar for Node.js. Prior to 7.5.16, tar (node-tar) applies a PAX extended header's size= record (and other PAX overrides) to the next header entry of any type, including int…
|
CWE-436
Interpretation Conflict
|
CVE-2026-53655
|
2026-06-24 00:50 |
2026-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1683
|
7.5 |
HIGH
Network
|
-
|
-
|
protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.6.1 and 8.4.1, protobufjs could recurse without a depth limit while converting decoded messages to plain objects or…
|
CWE-674
Uncontrolled Recursion
|
CVE-2026-48712
|
2026-06-24 00:50 |
2026-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1684
|
7.5 |
HIGH
Network
|
-
|
-
|
Python-Multipart is a streaming multipart parser for Python. Prior to 0.0.30, when parsing application/x-www-form-urlencoded bodies, QuerystringParser located the field separator with a two step look…
|
CWE-400 CWE-407
Uncontrolled Resource Consumption Inefficient Algorithmic Complexity
|
CVE-2026-53539
|
2026-06-24 00:50 |
2026-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1685
|
- |
|
-
|
-
|
http-proxy-middleware is node.js http-proxy middleware. From 0.16.0 until 2.0.10, 3.0.6, and 4.1.0, http-proxy-middleware documents router proxy-table entries as host, path, or host+path selectors, b…
|
CWE-20 CWE-187
Improper Input Validation Partial String Comparison
|
CVE-2026-55602
|
2026-06-24 00:50 |
2026-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1686
|
7.5 |
HIGH
Network
|
-
|
-
|
NLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and tutorials supporting research and development in Natural Language Processing. Prior to 3.10.0-rc1, nltk.data.l…
|
CWE-22
Path Traversal
|
CVE-2026-54293
|
2026-06-24 00:50 |
2026-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1687
|
5.1 |
MEDIUM
Local
|
-
|
-
|
LangChain is a framework for building agents and LLM-powered applications. Prior to 1.3.9, several LangChain components that resolve filesystem paths or expand search patterns do not consistently con…
|
CWE-22 CWE-59
Path Traversal Link Following
|
CVE-2026-55443
|
2026-06-24 00:50 |
2026-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1688
|
5.4 |
MEDIUM
Network
|
-
|
-
|
Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to 1.6.10 and 1.7.1, Authlib's OAuth 2.0 authorization endpoint can be turned into an unauthenticated open redirect wh…
|
CWE-601
Open Redirect
|
CVE-2026-41479
|
2026-06-24 00:50 |
2026-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1689
|
5.8 |
MEDIUM
Network
|
-
|
-
|
phpseclib is a PHP secure communications library. From 0.1.1 until 1.0.30, 2.0.55, and 3.0.54, when an application validates an untrusted X.509 certificate with phpseclib, X509::validateSignature() r…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-55599
|
2026-06-24 00:50 |
2026-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1690
|
6.5 |
MEDIUM
Network
|
-
|
-
|
UltraJSON is a fast JSON encoder and decoder written in pure C with bindings for Python 3.7+. Prior to 5.13.0, ujson.dumps() (or ujson.dump() or ujson.encode()) have a reject_bytes=False option. When…
|
CWE-20
Improper Input Validation
|
CVE-2026-54911
|
2026-06-24 00:50 |
2026-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|