CVE-2025-43529 [HIGH 8.8] depth=abyssal score=75 epss=9% (KEV,EXPLOITED) — A use-after-free issue was addressed with improved memory management CVE-2025-43520 [MEDIUM 5.5] depth=midnight score=55 epss=0% (KEV,EXPLOITED) — A memory corruption issue was addressed with improved memory handling CVE-2025-6558 [HIGH 8.8] depth=abyssal score=75 epss=10% (KEV,EXPLOITED) — Insufficient validation of untrusted input in ANGLE and GPU in Google Chrome prior to 138.0.7204.157 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page CVE-2025-11371 [HIGH 7.5] depth=abyssal score=85 epss=92% (KEV,EXPLOITED) — Gladinet CentreStack and TrioFox Local File Inclusion Flaw CVE-2026-62369 [HIGH 8.1] depth=twilight score=45 — KubeEdge: keadm DecompressTarGz path traversal enables arbitrary file write on Windows during edge node join CVE-2023-39329 [MEDIUM 6.5] depth=sunlit score=36 epss=1% — Openjpeg: resource exhaustion will occur in the opj_t1_decode_cblks function in the tcd.c CVE-2026-19611 [HIGH 7.4] depth=twilight score=41 epss=0% — Wildfly-elytron: org.wildfly.security/wildfly-elytron-password-impl: wildfly-elytron: password keyspace reduction via nfkc fullwidth folding CVE-2026-93012 [NONE] depth=sunlit score=3 — Email::Sender::Transport::Sendmail versions before 2.602 for Perl allow arbitrary command execution on Windows sending a message whose envelope address reaches the shell in _sendmail_pipe CVE-2026-92382 [MEDIUM 4.1] depth=sunlit score=23 — Usbredir: usbredir: unbounded iso_packet_desc[] index in usbredirhost_iso_packet() leads to heap out-of-bounds write CVE-2026-94488 [HIGH 8.2] depth=twilight score=45 — Telegram Desktop before 6.9.4 allows XSS in the HTML exporter CVE-2026-61612 [MEDIUM 5.7] depth=sunlit score=31 — @aborruso/ckan-mcp-server has SSRF via DNS-name → internal IP — incomplete fix of CVE-2026-53509 CVE-2026-48976 [HIGH 8.1] depth=twilight score=45 — HomeBox: Cross-Tenant IDOR in Notifier Update Leaks Shoutrrr Credentials and Allows Webhook Hijack CVE-2023-43000 [HIGH 8.8] depth=abyssal score=74 epss=4% (KEV,EXPLOITED) — A use-after-free issue was addressed with improved memory management CVE-2026-62182 [HIGH 8.8] depth=twilight score=48 — KubeEdge: ConfigUpdateJob updateFields enables remote shell injection and code execution on edge nodes CVE-2023-39327 [MEDIUM 4.3] depth=sunlit score=24 epss=1% — Openjpeg: malicious files can cause the program to enter a large loop CVE-2026-48975 [HIGH 8.1] depth=twilight score=45 — HomeBox: Cross-Tenant IDOR in MaintenanceEntry Update and Delete Allows Tampering and Destruction of Any User's Maintenance History in Homebox CVE-2026-48974 [MEDIUM 5.4] depth=sunlit score=30 — HomeBox: Forced Group Membership Without Consent in Homebox AddMember Handler CVE-2026-94449 [HIGH 7.5] depth=twilight score=41 — A flaw was found in the SmallRye Fault Tolerance library, which is used by Quarkus to provide strategies like retries and circuit breakers for microservices CVE-2026-77561 [MEDIUM 5.3] depth=sunlit score=29 — Tinyauth is an authentication and authorization server CVE-2026-63116 [HIGH 8.8] depth=twilight score=48 — deepstream is a server that allows clients and backend services to sync data, send messages and make rpcs at scale CVE-2026-62866 [MEDIUM 6.2] depth=sunlit score=34 — Dasel is a command-line tool and library for querying, modifying, and transforming data structures CVE-2026-62371 [HIGH 8.8] depth=twilight score=48 — KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at Edge CVE-2026-62370 [MEDIUM 6.5] depth=sunlit score=36 — KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at Edge CVE-2026-59168 [MEDIUM 6.2] depth=sunlit score=34 — Dasel is a command-line tool and library for querying, modifying, and transforming data structures CVE-2026-24552 [HIGH 8.5] depth=twilight score=47 epss=0% — Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in John-Michael L'Allier Create mediavine-create allows Blind SQL Injection.This issue affects Create: from n/a through 2.5.3. CVE-2026-83621 [HIGH 8.1] depth=twilight score=45 — ntopng is a web-based network traffic monitoring application CVE-2026-84990 [HIGH 8.8] depth=twilight score=48 — ntopng is a web-based network traffic monitoring application CVE-2026-62987 [MEDIUM 5.8] depth=sunlit score=32 — Fabio is an HTTP(S) and TCP router for deploying applications managed by consul CVE-2026-61674 [CRITICAL 9.2] depth=midnight score=51 — Fluent Bit is a fast and lightweight logs, metrics, and traces processor for Linux, BSD, macOS, and Windows CVE-2025-12548 [CRITICAL 9] depth=abyssal score=62 epss=1% — A flaw was found in Eclipse Che che-machine-exec CVE-2026-58504 [MEDIUM 6.1] depth=sunlit score=34 — draw.io is a configurable diagramming and whiteboarding application CVE-2026-63416 [LOW 3.7] depth=sunlit score=20 — draw.io is a configurable diagramming and whiteboarding application CVE-2026-78376 [HIGH 8.8] depth=twilight score=48 epss=0% — A flaw was found in WebKitGTK CVE-2026-63334 [MEDIUM 6.8] depth=sunlit score=37 — draw.io is a configurable diagramming and whiteboarding application CVE-2026-63373 [MEDIUM 4.2] depth=sunlit score=23 — draw.io is a configurable diagramming and whiteboarding application CVE-2026-76898 [HIGH 7.7] depth=twilight score=42 — draw.io is a configurable diagramming and whiteboarding application CVE-2026-79920 [CRITICAL 9.9] depth=midnight score=54 — Ajenti is a Linux & BSD modular server admin panel CVE-2026-17051 [MEDIUM 6] depth=sunlit score=33 — The Intel SEDI IPM (inter-processor mailbox) driver in drivers/ipm/ipm_sedi.c handles an inbound message interrupt in ipm_event_dispose() CVE-2026-17050 [MEDIUM 5.7] depth=sunlit score=31 — The experimental USB host stack allocates a per-device configuration-descriptor buffer, udev->cfg_desc, from the dedicated usb_device_heap in usbh_device_set_configuration() (subsys/usb/host/usbh_device.c) CVE-2026-77582 [MEDIUM 6.9] depth=sunlit score=38 — Tinyauth is an authentication and authorization server CVE-2026-77560 [HIGH 8.1] depth=twilight score=45 — Tinyauth is an authentication and authorization server RUSTSEC-2026-0297 [NONE] depth=sunlit score=3 — `unzip`: archive extraction is vulnerable to path traversal (zip-slip) RUSTSEC-2026-0296 [NONE] depth=sunlit score=3 — `unzip` is unmaintained CVE-2026-82412 [HIGH 8.8] depth=twilight score=48 — ntopng is a web-based network traffic monitoring application CVE-2026-36468 [MEDIUM 6.1] depth=sunlit score=34 — Cross-site Scripting (XSS) in index.php in CuteNews v.2.1.2 allows remote unauthenticated attackers to supply an arbitrarily named URL parameter key, with part of its name containing any URL-encoded common XSS payload (such as ">