Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 6.3 CVE-2026-54276

AIOHTTP: DigestAuthMiddleware Applies Credentials to Cross-Origin Redirect Challenges_CVE-2026-54276

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, DigestAuthMiddleware can send an authentication re...

aio-libs aiohttp < 3.14.1 CVE
MEDIUM 6.6 CVE-2026-54274

AIOHTTP: Incomplete websocket frame payloads bypass memory limits_CVE-2026-54274

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, if an attacker sends large incomplete websocket fr...

aio-libs aiohttp < 3.14.1 CVE
MEDIUM 6.6 CVE-2026-54273

AIOHTTP: HTTP/1 Pipelined Requests Queue Without Limit_CVE-2026-54273

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, no limit was present on the number of pipelined re...

aio-libs aiohttp < 3.14.1 CVE
MEDIUM 5.3 CVE-2026-54270

protobufjs: Memory amplification from preserved unknown fields in binary decode_CVE-2026-54270

protobufjs compiles protobuf definitions into JavaScript (JS) functions. From 8.2.0 to 8.4.2, protobufjs preserved unknown wire elements in message...

protobufjs protobuf.js >=8.2.0, < 8.5.0 CVE
MEDIUM 5.3 CVE-2026-54269

protobufjs: Schema-derived names can shadow runtime-significant properties_CVE-2026-54269

protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 8.6.0 and 7.6.3, protobufjs accepted certain schema-derived names...

protobufjs protobuf.js < 7.6.3 CVE
MEDIUM 5.5 CVE-2026-53632

NTLMv2 hash disclosure via UNC path handling on Windows_CVE-2026-53632

launch-editor allows users to open files with line numbers in editor from Node.js. Prior to 2.14.1, the launch-editor NPM package accesses arbitrar...

vitejs launch-editor < 2.14.1 CVE
MEDIUM 5.7 CVE-2026-50184

Angular: Request Credential & Cache Policy Stripping in Angular Service Worker_CVE-2026-50184

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 22.0.0...

angular angular >= 22.0.0-next.0, < 22.0.0-rc.2 CVE
MEDIUM 5.7 CVE-2026-50169

Angular Service Worker Policy-Bypass & Credential-Stripping Vulnerabilities_CVE-2026-50169

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 22.0.0...

angular angular >= 22.0.0-next.0, < 22.0.0-rc.2 CVE
MEDIUM 4.8 CVE-2026-11994

Akaunting 3.1.21 – Authenticated stored XSS in report description rendering_CVE-2026-11994

Akaunting 3.1.21 contains an authenticated stored Cross-Site Scripting vulnerability in the report management workflow. A user with permission to c...

Akaunting Akaunting 3.1.21 CVE
MEDIUM 5.9 A63E68C2-3F8F-

Exploit for Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) in Trustwallet Trust_Wallet_Browser_Extension_A63E68C2-3F8F-5064-93CE-8E4051079D14

DONATE: bc1qps62cyk9f9unmdkc9k3ccj9e2h8ywfhg2j53ec Built with ❤️ for the crypto research community. 🚀 CVE-2023-31290 Scanner - Bitcoin & Ethereum ...

N/A N/A GITHUBEXPLOIT