Recent Advisories

Severity ID Title Vendor Product Date Type
LOW 2.1 CVE-2026-54906

concurrent-ruby: ReadWriteLock allows wrong-thread write release and stray read-release counter corruption_CVE-2026-54906

concurrent-ruby is a modern concurrency tools for Ruby. Prior to 1.3.7, Concurrent::ReadWriteLock#release_write_lock does not verify that the calli...

ruby-concurrency concurrent-ruby < 1.3.7 CVE
LOW 2 CVE-2026-54905

concurrent-ruby: `ReentrantReadWriteLock` read-count overflow grants a write lock without exclusivity_CVE-2026-54905

concurrent-ruby is a modern concurrency tools for Ruby. Prior to 1.3.7, Concurrent::ReentrantReadWriteLock can incorrectly grant a write lock after...

ruby-concurrency concurrent-ruby < 1.3.7 CVE
LOW 3.7 CVE-2026-57288

CVE-2026-57288_CVE-2026-57288

Jenkins Active Directory Plugin 2.41.1 and earlier does not escape the user name before building the LDAP search filter in the Windows native (ADSI...

Jenkins Project Jenkins Active Directory Plugin CVE
LOW 2.7 CVE-2026-10753

Site Kit by Google < 1.176.0 - Editor+ Email Reporting Settings Update_CVE-2026-10753

The Site Kit by Google WordPress plugin before 1.176.0 does not properly restrict a REST API write endpoint to administrators, allowing lower-priv...

Unknown Site Kit by Google CVE
LOW 1.1 CVE-2026-13140

Stored Cross-Site Scripting in Canarytokens.org_CVE-2026-13140

Stored Cross-Site Scripting in the exposed AWS API key store of Thinkst Applied Research Canarytokens. Anonymous exploitation requires knowledg...

Thinkst Applied Research Canarytokens sha-4116b92cb CVE
LOW 2.3 CVE-2026-46554

NocoDB: Stale Auth Cache After API Token Deletion_CVE-2026-46554

NocoDB is software for building databases as spreadsheets. Prior to 2026.04.4, deleted API tokens continued to authenticate requests until their ca...

nocodb nocodb < 2026.04.4 CVE
LOW 2.1 CVE-2026-46553

NocoDB: Attachment Size Limit Bypass via Upload-by-URL_CVE-2026-46553

NocoDB is software for building databases as spreadsheets. Prior to 2026.04.1, the upload-by-URL path did not enforce NC_ATTACHMENT_FIELD_SIZE agai...

nocodb nocodb < 2026.04.1 CVE
LOW 2 CVE-2026-46549

NocoDB: OAuth Token Scope Not Enforced at ACL Layer Allows Scope Escalation_CVE-2026-46549

NocoDB is software for building databases as spreadsheets. Prior to 2026.04.1, the OAuth token strategy attached oauth_scope and oauth_granted_reso...

nocodb nocodb < 2026.04.1 CVE
LOW 2.2 CVE-2026-54327

Pi: Race condition in auth.json writes could expose stored credentials_CVE-2026-54327

Pi is a minimal terminal coding harness. From 0.74.0 until 0.78.1, Pi stored API keys and OAuth credentials in auth.json. A race condition in the f...

earendil-works pi >= 0.74.0, < 0.78.1 CVE
LOW 2.5 CVE-2026-54326

Pi: Potential XSS in HTML session exports via Markdown URL sanitization bypass_CVE-2026-54326

Pi is a minimal terminal coding harness. From 0.74.0 until 0.78.1, Pi HTML exports render session Markdown into a static HTML file. It did not cons...

earendil-works pi >= 0.74.0, < 0.78.1 CVE