Recent Advisories

Severity ID Title Vendor Product Date Type
LOW 2.3 CVE-2026-7085

HBAI-Ltd Toonflow-app downloadApp Endpoint downloadApp.ts z.url path traversal_CVE-2026-7085

A vulnerability was determined in HBAI-Ltd Toonflow-app up to 1.1.1. This vulnerability affects the function z.url of the file src/routes/setting/a...

HBAI-Ltd Toonflow-app 1.1.0 CVE
LOW 3.1 CVE-2026-41488

angchain-openai: Image token counting SSRF protection can be bypassed via DNS rebinding_CVE-2026-41488

LangChain is a framework for building agents and LLM-powered applications. Prior to 1.1.14, langchain-openai's _url_to_size() helper (used by get_n...

langchain-ai langchain-openai < 1.1.14 CVE
LOW 3.8 CVE-2026-31051

CVE-2026-31051_CVE-2026-31051

An issue in Hostbill v.2025-11-24 and 2025-12-01 allows a remote attacker to cause a denial of service via the Client Balance component

n/a n/a n/a CVE
LOW 1.7 CVE-2026-41677

rust-openssl: Out-of-bounds read in PEM password callback when user callback returns an oversized length_CVE-2026-41677

rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.9.0 to before 0.10.78, the *_from_pem_callback APIs did not valid...

rust-openssl rust-openssl >= 0.9.0, < 0.10.78 CVE
LOW 2.2 CVE-2026-41321

@astrojs/cloudflare: SSRF via redirect following in Cloudflare image-binding-transform endpoint_CVE-2026-41321

@astrojs/cloudflare is an SSR adapter for use with Cloudflare Workers targets. Prior to 13.1.10, the fetch() call for remote images in packages/int...

withastro @astrojs/cloudflare < 13.1.10 CVE
LOW 0.6 CVE-2026-41140

Poetry: Path traversal in tar extraction on Python 3.10.0 – 3.10.12 and 3.11.0 – 3.11.4_CVE-2026-41140

Poetry is a dependency manager for Python. Prior to 2.3.4, the extractall() function in src/poetry/utils/helpers.py:410-426 extracts sdist tarballs...

python-poetry poetry < 2.3.4 CVE
LOW 3.7 CVE-2026-42040

Axios: Null Byte Injection via Reverse-Encoding in AxiosURLSearchParams_CVE-2026-42040

Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, the encode() function in lib/helpers/AxiosURLSearchPa...

axios axios >= 1.0.0, < 1.15.1 CVE
LOW 2.4 CVE-2026-4313

Stored XSS in AdaptiveGRC_CVE-2026-4313

AdaptiveGRC is vulnerable to Stored XSS via text type fields across the forms. Authenticated attacker can replace the value of the text field in th...

C&F AdaptiveGRC 5.420.00 CVE
LOW 2.1 MS:CVE-2026-5958

Race Condition in GNU Sed_MS:CVE-2026-5958

{“lastseen”:”2026-04-24T07:13:17″,”description”:””,”published”:”2026-04-22T08:01:...

N/A N/A MSCVE
LOW 1.3 CVE-2026-41430

Press vulnerable to reflected XSS on login redirection_CVE-2026-41430

Press, a Frappe custom app that runs Frappe Cloud, manages infrastructure, subscription, marketplace, and software-as-a-service (SaaS). Redirect pa...

frappe press < 16d1b6ca2559f858a1de77bcb03fd7f1b81671c6 CVE