|
471
|
6.5 |
MEDIUM
Network
|
ultrajson_project
|
ultrajson
|
UltraJSON is a fast JSON encoder and decoder written in pure C with bindings for Python 3.7+. Prior to 5.13.0, ujson.dumps() (or ujson.dump() or ujson.encode()) have a reject_bytes=False option. When…
New
|
CWE-20
Improper Input Validation
|
CVE-2026-54911
|
2026-06-27 05:10 |
2026-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
472
|
5.4 |
MEDIUM
Network
|
authlib
|
authlib
|
Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to 1.6.10 and 1.7.1, Authlib's OAuth 2.0 authorization endpoint can be turned into an unauthenticated open redirect wh…
New
|
CWE-601
Open Redirect
|
CVE-2026-41479
|
2026-06-27 05:10 |
2026-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
473
|
5.8 |
MEDIUM
Network
|
phpseclib
|
phpseclib
|
phpseclib is a PHP secure communications library. From 0.1.1 until 1.0.30, 2.0.55, and 3.0.54, when an application validates an untrusted X.509 certificate with phpseclib, X509::validateSignature() r…
New
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-55599
|
2026-06-27 05:10 |
2026-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
474
|
6.1 |
MEDIUM
Network
|
fabricjs
|
fabric.js
|
Fabric.js is a Javascript HTML5 canvas library. Prior to 7.4.0, a potential Cross-Site Scripting (XSS) vulnerability exists in Fabric.js due to improper escaping of user-controlled input during SVG s…
New
|
CWE-79 CWE-116
Cross-site Scripting Improper Encoding or Escaping of Output
|
CVE-2026-44311
|
2026-06-27 05:09 |
2026-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
475
|
6.1 |
MEDIUM
Network
|
pylonsproject
|
webob
|
WebOb provides objects for HTTP requests and responses. Prior to 1.8.10, the normalization of the HTTP Location header during a redirect is vulnerable to an open redirect: WebOb joins the redirect ta…
New
|
CWE-601
Open Redirect
|
CVE-2026-44889
|
2026-06-27 05:08 |
2026-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
476
|
8.6 |
HIGH
Network
|
chimurai
|
http-proxy-middleware
|
http-proxy-middleware is node.js http-proxy middleware. From 0.16.0 until 2.0.10, 3.0.6, and 4.1.0, http-proxy-middleware documents router proxy-table entries as host, path, or host+path selectors, b…
New
|
CWE-20 CWE-187
Improper Input Validation Partial String Comparison
|
CVE-2026-55602
|
2026-06-27 05:06 |
2026-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
477
|
7.5 |
HIGH
Network
|
nltk
|
nltk
|
NLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and tutorials supporting research and development in Natural Language Processing. Prior to 3.10.0-rc1, nltk.data.l…
New
|
CWE-22
Path Traversal
|
CVE-2026-54293
|
2026-06-27 05:06 |
2026-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
478
|
6.1 |
MEDIUM
Network
|
ibm
|
engineering_workflow_management
|
IBM Engineering Workflow Management 7.0.2 through 7.0.2 Interim Fix 035, 7.0.3 through 7.0.3 Interim Fix 017, and 7.1 through 7.1 Interim Fix 004 is vulnerable to HTTP header injection, caused by imp…
New
|
CWE-644
Improper Neutralization of HTTP Headers for Scripting Syntax
|
CVE-2024-51454
|
2026-06-27 05:05 |
2026-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
479
|
5.5 |
MEDIUM
Local
|
langchain
|
langchain
|
LangChain is a framework for building agents and LLM-powered applications. Prior to 1.3.9, several LangChain components that resolve filesystem paths or expand search patterns do not consistently con…
New
|
CWE-22 CWE-59
Path Traversal Link Following
|
CVE-2026-55443
|
2026-06-27 05:05 |
2026-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
480
|
3.6 |
LOW
Local
|
babel
|
babel
|
Babel is a compiler for writing next generation JavaScript. Prior to 8.0.0-rc.6 and 7.29.6, @babel/core affected by an arbitrary file read via a sourceMappingURL comment. Using @babel/core to compile…
New
|
CWE-22 CWE-200
Path Traversal Information Exposure
|
CVE-2026-49356
|
2026-06-27 05:04 |
2026-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|