Recent Advisories

Severity ID Title Vendor Product Date Type
LOW 2.3 CVE-2026-13507

volcengine OpenViking Local VectorDB Primary-key Label str_to_uint64.py str_to_uint64 data authenticity_CVE-2026-13507

A vulnerability was detected in volcengine OpenViking up to 0.3.21. This affects the function str_to_uint64 of the file openviking/storage/vectordb...

volcengine OpenViking 0.3.0 CVE
MEDIUM 5.3 CVE-2026-13509

RAGapp Knowledge File files.py FileHandler.remove_file path traversal_CVE-2026-13509

A vulnerability has been found in RAGapp up to 0.1.5. Affected is the function FileHandler.upload_file/FileHandler.remove_file of the file src/raga...

n/a RAGapp 0.1.0 CVE
MEDIUM 5.1 CVE-2026-13508

khoj-ai khoj Conversation Sharing api_chat.py authorization_CVE-2026-13508

A flaw has been found in khoj-ai khoj up to 2.0.0-beta.28. This impacts an unknown function of the file src/khoj/routers/api_chat.py of the compone...

khoj-ai khoj 2.0.0-beta.0 CVE
MEDIUM 5.1 CVE-2026-13504

code-projects Project Management System Mail Compose mail.php cross site scripting_CVE-2026-13504

A vulnerability has been found in code-projects Project Management System 1.0. This vulnerability affects unknown code of the file /mail.php of the...

code-projects Project Management System 1.0 CVE
MEDIUM 6.9 CVE-2026-13503

antlr ANTLR4 tokenVocab Grammar Option TokenVocabParser.java getImportedVocabFile path traversal_CVE-2026-13503

A vulnerability was detected in antlr ANTLR4 up to 4.13.2. Affected by this issue is the function getImportedVocabFile of the file tool/src/org/ant...

antlr ANTLR4 4.13.0 CVE
LOW 2 CVE-2026-13502

antlr ANTLR4 Maven Plugin GrammarDependencies.java ObjectInputStream.readObject toctou_CVE-2026-13502

A flaw has been found in antlr ANTLR4 up to 4.13.2. This affects the function ObjectInputStream.readObject of the file antlr4-maven-plugin/src/main...

antlr ANTLR4 4.13.0 CVE
MEDIUM 4.8 CVE-2026-13501

antlr ANTLR4 gofmt GoTarget.java GoTarget command injection_CVE-2026-13501

A security vulnerability has been detected in antlr ANTLR4 up to 4.13.2. Affected by this vulnerability is the function GoTarget of the file tool/s...

antlr ANTLR4 4.13.0 CVE
MEDIUM 6.9 CVE-2026-13498

yashpokharna2555 restaurent-management-system POST Parameter forgotpassword.php sql injection_CVE-2026-13498

A vulnerability was identified in yashpokharna2555 restaurent-management-system. This affects an unknown function of the file /forgotpassword.php o...

yashpokharna2555 restaurent-management-system 5f3eca87cb681366866a78038af17891c4c86612 CVE
MEDIUM 5.3 CVE-2026-13497

itsourcecode Hospital Management System appointment.php sql injection_CVE-2026-13497

A vulnerability was determined in itsourcecode Hospital Management System 1.0. The impacted element is an unknown function of the file /appointment...

itsourcecode Hospital Management System 1.0 CVE
MEDIUM 5.3 CVE-2026-13499

yashpokharna2555 restaurent-management-system Registration login_register.php cross site scripting_CVE-2026-13499

A security flaw has been discovered in yashpokharna2555 restaurent-management-system. This impacts an unknown function of the file login_register.p...

yashpokharna2555 restaurent-management-system 5f3eca87cb681366866a78038af17891c4c86612 CVE