Sources:
amazon_linux
archlinux
azure_linux
bitnami_vulndb
capec
capec_enrichment_dashboard
certeu
certfr
circl_kev
cisa_known_exploited
cna_scorecard
cnvd
csaf_abb
csaf_adstecindustrialitgmbh
csaf_amd
csaf_aumariestergmbhcokg
csaf_baadem2mproductsgmbh
csaf_beckhoffautomationgmbhcokg
csaf_bendergmbhcokg
csaf_bosch
csaf_bsi
csaf_bsi_aggregator
csaf_bsi_cvd_white
csaf_bsi_white
csaf_bsi_wid_white
csaf_carlogavazziautomation
csaf_certbund
csaf_certvde
csaf_cisa
csaf_cisa_it
csaf_cisa_ot
csaf_cisco
csaf_claaskgaa
csaf_codesysgmbh
csaf_dell
csaf_duraggmbh
csaf_endresshauserag
csaf_ericsson
csaf_euchnergmbhcokg
csaf_festosecokg
csaf_frauschersensortechnikgmbh
csaf_hancom
csaf_harmaninternational
csaf_helmholzgmbhcokg
csaf_himapaulhildebrandtgmbh
csaf_hitachi
csaf_hpe
csaf_huawei
csaf_hydacinternationalgmbh
csaf_ibm
csaf_ifmelectronicgmbh
csaf_janitzaelectronicsgmbh
csaf_jumogmbhcokg
csaf_juniper
csaf_kebautomationkg
csaf_kukaag
csaf_lenovo
csaf_lenzese
csaf_mbconnectlinegmbh
csaf_mettlertoledogmbh
csaf_metzconnectgmbh
csaf_microsoft
csaf_mieleciekg
csaf_moxa
csaf_murrelektronikgmbh
csaf_ncscnl
csaf_ndaal
csaf_netapp
csaf_nozomi
csaf_nozominetworks
csaf_nvidia
csaf_opcfoundation
csaf_openeuler
csaf_opensuse
csaf_oracle
csaf_ox
csaf_paloalto
csaf_panasonic
csaf_pentagrid
csaf_pepperlfuchsse
csaf_phoenix
csaf_pilzgmbhcokg
csaf_qnap
csaf_redhat
csaf_samsung
csaf_sauterag
csaf_schneider
csaf_sick
csaf_siemens
csaf_smasolartechnologyag
csaf_suse
csaf_swarcotrafficsystemsgmbh
csaf_synology
csaf_tibco
csaf_trend
csaf_trumpfsecokg
csaf_trustsource
csaf_tuxcare
csaf_ubiquiti
csaf_vartastoragegmbh
csaf_vegagrieshaberkg
csaf_vmware
csaf_wagogmbhcokg
csaf_weidmuellerinterfacegmbhcokg
csaf_welotecgmbh
csaf_wiesemanntheisgmbh
csaf_yaskawaeuropegmbh
csaf_yokogawa
csaf_zyxel
cve_forecast
cve_icu
cve_vs_github_dashboard
cvelistv5
cwe_dashboard
cwe_enrichment
cwec
debian_security_tracker
drupal
emb3d
emb3d_dashboard
epss_dashboard
epss_history
epss_kev_enrichment
euvd_kev
fedora
fkie_nvd
freebsd
gcve
gcve_enriched
gcve_enrichment
gcve_enrichment_dashboard
gentoo
github
gsd
jvn
kev_ransomware
mitre_attack
moksha
ndaal_kev
netbsd
nuclei_dashboard
nuclei_enrichment
nvd
nvd_cpe_dictionary
openbsd
opencve
oracle_linux
ossf_malicious_packages
osv_almalinux
osv_alpine
osv_bellsoft
osv_chainguard
osv_cran
osv_github_actions
osv_golang
osv_haskell
osv_hex
osv_maven
osv_npm
osv_nuget
osv_ocaml
osv_ossfuzz
osv_packagist
osv_pub
osv_rocky
osv_rubygems
osv_rustsec
osv_swift
osv_ubuntu
osv_wolfi
publish_stats
pysec
sadp_pilot
ssvc
ssvc_dashboard
tailscale
tsunami_enrichment
variot
vulnrichment
Clear
| ID | Title | Severity | CVSS | Source | Updated |
|---|---|---|---|---|---|
| eef-cve-2026-89420 | Session voucher adding no new funds is accepted without a charge in mpp, serving paid resources for free | UNKNOWN | 7.1 | osv_hex | unknown |
| eef-cve-2026-87119 | mpp Tempo subscription key authorization is not bound to the issuing challenge, allowing a captured activation credential to be replayed | UNKNOWN | 8.2 | osv_hex | unknown |
| eef-cve-2025-48044 | Authorization bypass when bypass policy condition evaluates to true | UNKNOWN | 8.6 | osv_hex | unknown |
| eef-cve-2025-48043 | Bypass and runtime policies that can never pass may be incorrectly applied in filter authorization | UNKNOWN | 8.6 | osv_hex | unknown |
| eef-cve-2025-48042 | Before action hooks may execute in certain scenarios despite a request being forbidden | UNKNOWN | 7.1 | osv_hex | unknown |
| eef-cve-2025-4754 | Missing Session Revocation on Logout in ash_authentication_phoenix | UNKNOWN | 2.3 | osv_hex | unknown |
| eef-cve-2026-82672 | Unvalidated chunk-size line tail in Mint HTTP/1 client enables response smuggling against strict intermediaries on pooled connections | UNKNOWN | 6.3 | osv_hex | unknown |
| eef-cve-2026-86688 | Session id is not renewed on authentication in ash_authentication, allowing session fixation | UNKNOWN | 7.4 | osv_hex | unknown |
| eef-cve-2026-76949 | Remember-me sign-in guard reads a session key that is never written in ash_authentication, allowing session replacement | UNKNOWN | 9.1 | osv_hex | unknown |
| eef-cve-2026-91039 | dynamic_oidc identities are not namespaced by connection in ash_authentication, allowing cross-connection account takeover | UNKNOWN | 9.1 | osv_hex | unknown |
| eef-cve-2026-88952 | OAuth2 sign-in attached to an existing account without an email comparison in AshAuthentication | UNKNOWN | 9.1 | osv_hex | unknown |
| eef-cve-2026-86533 | Revoked session accepted because the session jti is never checked in AshAuthentication and AshAuthentication Phoenix | UNKNOWN | 9.1 | osv_hex | unknown |
| eef-cve-2026-82760 | Superlinear base62 decoding exhausts CPU and memory in AshAuthentication API key sign-in | UNKNOWN | 8.2 | osv_hex | unknown |
| eef-cve-2026-82759 | Reversible IP address pseudonymisation in AshAuthentication audit log hash mode | UNKNOWN | 1.8 | osv_hex | unknown |
| eef-cve-2026-82685 | Confirmation token accepted on any record in AshAuthentication | UNKNOWN | 7.6 | osv_hex | unknown |
| eef-cve-2026-81632 | Single-use sign-in token placed in a redirect query string in AshAuthenticationPhoenix | UNKNOWN | 7.2 | osv_hex | unknown |
| eef-cve-2026-78223 | Token revocation record built from unverified JWT claims in AshAuthentication | UNKNOWN | 6.9 | osv_hex | unknown |
| eef-cve-2026-86522 | Log injection via an unescaped password reset identity in AshAuthentication | UNKNOWN | 6.3 | osv_hex | unknown |
| eef-cve-2026-85500 | `require_confirmed_with` is not enforced on the action and fails open on an unreadable attribute in AshAuthentication | UNKNOWN | 9.1 | osv_hex | unknown |
| eef-cve-2026-82761 | Magic link single-use tokens replayable via TOCTOU race in AshAuthentication | UNKNOWN | 9.1 | osv_hex | unknown |
| eef-cve-2026-82723 | Actor record with password digest stored in AshAuthentication audit log entries | UNKNOWN | 1.8 | osv_hex | unknown |
| eef-cve-2026-81637 | Replayable OAuth2 CSRF state retained after a failed callback in AshAuthentication | UNKNOWN | 2.3 | osv_hex | unknown |
| eef-cve-2026-80218 | Sign-in token minted for one resource accepted by another in AshAuthentication | UNKNOWN | 7.6 | osv_hex | unknown |
| eef-cve-2026-43971 | Link Header Directive Smuggling via Unescaped target/rel/Attribute Keys in cow_link:link/1 | UNKNOWN | 6.3 | osv_hex | unknown |
| eef-cve-2026-89186 | mpp writes Payment-Receipt and Cache-Control before the wrapped application runs, letting a consumer's own Cache-Control expose paid responses to shared caches | UNKNOWN | 6.3 | osv_hex | unknown |
| eef-cve-2026-88255 | mpp Tempo keys its pre-broadcast dedup reserve on the caller-supplied transaction encoding, so a re-encoded signed transaction reserves a second slot | UNKNOWN | 6.3 | osv_hex | unknown |
| eef-cve-2026-86338 | Ash field policies do not filter-nil forbidden calculations and aggregates, enabling an information-disclosure oracle | UNKNOWN | 6.0 | osv_hex | unknown |
| eef-cve-2026-77972 | safeurl validated address is not bound to the request, allowing DNS rebinding | UNKNOWN | 9.0 | osv_hex | unknown |
| eef-cve-2026-77866 | SSRF protection bypass in safeurl via IPv6 addresses and unresolvable hosts | UNKNOWN | 9.0 | osv_hex | unknown |
| ghsa-76v6-f83q-pxvh | Duplicate Advisory: Hackney has an Allocation of Resources Without Limits or Throttling vulnerabilit | UNKNOWN | 8.2 | ghsa | unknown |