New CVEs

topic · security/cve-published
DOC.
security/cve-published
REV.
2,988 evt
DATE.
08-JUN-2026
SCOPE.
custom
§01

about

Recently published CVE vulnerability records with CVSS scores (CIRCL).

§02

recent events

LIVElast event 0s ago0 evt / 1h

showing 10 of 2,911 events in this window (2,988 total on topic). adjust the range or clear it with ALL.

range
iso 8601 utc
iso 8601 utc
01GHSA-6wcc-39rp-hh9p@hypequery/clickhouse has SQL Injection in parameter escaping that allows arbitrary SQL execution{"url":"https://www.cve.org/CVERecord?id=GHSA-6wcc-39rp-hh9p","cvss":null,"cve_i…
EVENT. cms5aqxzID. cms5aqxzwacexkh0clxe1zwhaSRC. key:cmpxakb6
{
  "url": "https://www.cve.org/CVERecord?id=GHSA-6wcc-39rp-hh9p",
  "cvss": null,
  "cve_id": "GHSA-6wcc-39rp-hh9p",
  "source": "circl",
  "summary": "@hypequery/clickhouse has SQL Injection in parameter escaping that allows arbitrary SQL execution",
  "severity": null,
  "references": [
    {
      "url": "https://github.com/hypequery/hypequery/security/advisories/GHSA-6wcc-39rp-hh9p",
      "type": "WEB"
    },
    {
      "url": "https://github.com/hypequery/hypequery/commit/4dfa9d77d70a08b970e722268b75ca7d13db0bdf",
      "type": "WEB"
    },
    {
      "url": "https://github.com/hypequery/hypequery",
      "type": "PACKAGE"
    },
    {
      "url": "https://github.com/hypequery/hypequery/blob/main/packages/clickhouse/CHANGELOG.md#202",
      "type": "WEB"
    },
    {
      "url": "https://github.com/hypequery/hypequery/releases/tag/@hypequery/[email protected]",
      "type": "WEB"
    }
  ],
  "updated_at": null,
  "published_at": null
}
02GHSA-fh2f-xfxc-q9ccopenhole-server vulnerable to path traversal via URL-decoded request path{"url":"https://www.cve.org/CVERecord?id=GHSA-fh2f-xfxc-q9cc","cvss":null,"cve_i…
EVENT. cms5aqxeID. cms5aqxezacevkh0c4tgdcw16SRC. key:cmpxakb6
{
  "url": "https://www.cve.org/CVERecord?id=GHSA-fh2f-xfxc-q9cc",
  "cvss": null,
  "cve_id": "GHSA-fh2f-xfxc-q9cc",
  "source": "circl",
  "summary": "openhole-server vulnerable to path traversal via URL-decoded request path",
  "severity": null,
  "references": [
    {
      "url": "https://github.com/bablilayoub/openhole/security/advisories/GHSA-fh2f-xfxc-q9cc",
      "type": "WEB"
    },
    {
      "url": "https://github.com/bablilayoub/openhole/commit/a28c27adde2a7ed0c347b730c8707208c0f78ed3",
      "type": "WEB"
    },
    {
      "url": "https://github.com/bablilayoub/openhole",
      "type": "PACKAGE"
    },
    {
      "url": "https://github.com/bablilayoub/openhole/releases/tag/v0.1.2",
      "type": "WEB"
    }
  ],
  "updated_at": null,
  "published_at": null
}
03MAL-2026-10750Malicious code in telemetry-metrics (npm){"url":"https://www.cve.org/CVERecord?id=MAL-2026-10750","cvss":null,"cve_id":"M…
EVENT. cms4tn0iID. cms4tn0iva7pvkh0cl9mmg4txSRC. key:cmpxakb6
{
  "url": "https://www.cve.org/CVERecord?id=MAL-2026-10750",
  "cvss": null,
  "cve_id": "MAL-2026-10750",
  "source": "circl",
  "summary": "Malicious code in telemetry-metrics (npm)",
  "severity": null,
  "references": [
    {
      "url": "https://www.npmjs.com/package/telemetry-metrics/v/0.2.1",
      "type": "PACKAGE"
    },
    {
      "url": "https://www.npmjs.com/package/telemetry-metrics/v/0.2.5",
      "type": "PACKAGE"
    }
  ],
  "updated_at": null,
  "published_at": null
}
04MAL-2026-10981Malicious code in streak-calendar (npm){"url":"https://www.cve.org/CVERecord?id=MAL-2026-10981","cvss":null,"cve_id":"M…
EVENT. cms4tmzzID. cms4tmzz6a7ptkh0c98ns9qegSRC. key:cmpxakb6
{
  "url": "https://www.cve.org/CVERecord?id=MAL-2026-10981",
  "cvss": null,
  "cve_id": "MAL-2026-10981",
  "source": "circl",
  "summary": "Malicious code in streak-calendar (npm)",
  "severity": null,
  "references": [
    {
      "url": "https://github.com/advisories/GHSA-2p69-mmpj-h84r",
      "type": "ADVISORY"
    },
    {
      "url": "https://www.npmjs.com/package/streak-calendar/v/1.0.1",
      "type": "PACKAGE"
    }
  ],
  "updated_at": null,
  "published_at": null
}
05MAL-2026-10988Malicious code in react-tabulix-ui (npm){"url":"https://www.cve.org/CVERecord?id=MAL-2026-10988","cvss":null,"cve_id":"M…
EVENT. cms4tmzfID. cms4tmzfla7prkh0cs2a78d71SRC. key:cmpxakb6
{
  "url": "https://www.cve.org/CVERecord?id=MAL-2026-10988",
  "cvss": null,
  "cve_id": "MAL-2026-10988",
  "source": "circl",
  "summary": "Malicious code in react-tabulix-ui (npm)",
  "severity": null,
  "references": [
    {
      "url": "https://github.com/advisories/GHSA-5jr9-f9w4-93v3",
      "type": "ADVISORY"
    },
    {
      "url": "https://www.npmjs.com/package/react-tabulix-ui/v/0.1.1",
      "type": "PACKAGE"
    },
    {
      "url": "https://www.npmjs.com/package/react-tabulix-ui/v/0.1.0",
      "type": "PACKAGE"
    }
  ],
  "updated_at": null,
  "published_at": null
}
06MAL-2026-11015Malicious code in react-tabulix-query (npm){"url":"https://www.cve.org/CVERecord?id=MAL-2026-11015","cvss":null,"cve_id":"M…
EVENT. cms4tmywID. cms4tmyw0a7ppkh0c94hmfyqfSRC. key:cmpxakb6
{
  "url": "https://www.cve.org/CVERecord?id=MAL-2026-11015",
  "cvss": null,
  "cve_id": "MAL-2026-11015",
  "source": "circl",
  "summary": "Malicious code in react-tabulix-query (npm)",
  "severity": null,
  "references": [
    {
      "url": "https://github.com/advisories/GHSA-4rrq-g9w7-39c3",
      "type": "ADVISORY"
    },
    {
      "url": "https://www.npmjs.com/package/react-tabulix-query/v/0.1.2",
      "type": "PACKAGE"
    },
    {
      "url": "https://www.npmjs.com/package/react-tabulix-query/v/0.1.0",
      "type": "PACKAGE"
    },
    {
      "url": "https://www.npmjs.com/package/react-tabulix-query/v/0.1.3",
      "type": "PACKAGE"
    }
  ],
  "updated_at": null,
  "published_at": null
}
07MAL-2026-11036Malicious code in streak-lib-math (npm){"url":"https://www.cve.org/CVERecord?id=MAL-2026-11036","cvss":null,"cve_id":"M…
EVENT. cms4tmycID. cms4tmycca7pnkh0cr358amldSRC. key:cmpxakb6
{
  "url": "https://www.cve.org/CVERecord?id=MAL-2026-11036",
  "cvss": null,
  "cve_id": "MAL-2026-11036",
  "source": "circl",
  "summary": "Malicious code in streak-lib-math (npm)",
  "severity": null,
  "references": [
    {
      "url": "https://github.com/advisories/GHSA-c7rv-9j9g-pqh2",
      "type": "ADVISORY"
    },
    {
      "url": "https://www.npmjs.com/package/streak-lib-math/v/1.0.0",
      "type": "PACKAGE"
    }
  ],
  "updated_at": null,
  "published_at": null
}
08MAL-2026-11040Malicious code in react-tabulix-extended (npm){"url":"https://www.cve.org/CVERecord?id=MAL-2026-11040","cvss":null,"cve_id":"M…
EVENT. cms4tmxsID. cms4tmxsba7plkh0ckj24bv38SRC. key:cmpxakb6
{
  "url": "https://www.cve.org/CVERecord?id=MAL-2026-11040",
  "cvss": null,
  "cve_id": "MAL-2026-11040",
  "source": "circl",
  "summary": "Malicious code in react-tabulix-extended (npm)",
  "severity": null,
  "references": [
    {
      "url": "https://www.npmjs.com/package/react-tabulix-extended/v/0.1.7",
      "type": "PACKAGE"
    }
  ],
  "updated_at": null,
  "published_at": null
}
09MAL-2026-11043Malicious code in supplyhub (npm){"url":"https://www.cve.org/CVERecord?id=MAL-2026-11043","cvss":null,"cve_id":"M…
EVENT. cms4tmx8ID. cms4tmx8ka7pjkh0c1l3cz0woSRC. key:cmpxakb6
{
  "url": "https://www.cve.org/CVERecord?id=MAL-2026-11043",
  "cvss": null,
  "cve_id": "MAL-2026-11043",
  "source": "circl",
  "summary": "Malicious code in supplyhub (npm)",
  "severity": null,
  "references": [
    {
      "url": "https://research.codelake.dev/advisories/clr-2026-3038-supplyhub",
      "type": "ADVISORY"
    },
    {
      "url": "https://www.npmjs.com/package/supplyhub/v/1.0.2",
      "type": "PACKAGE"
    }
  ],
  "updated_at": null,
  "published_at": null
}
10MAL-2026-6406Malicious code in syspo (npm){"url":"https://www.cve.org/CVERecord?id=MAL-2026-6406","cvss":null,"cve_id":"MA…
EVENT. cms4tmwoID. cms4tmwola7phkh0ctqo15utsSRC. key:cmpxakb6
{
  "url": "https://www.cve.org/CVERecord?id=MAL-2026-6406",
  "cvss": null,
  "cve_id": "MAL-2026-6406",
  "source": "circl",
  "summary": "Malicious code in syspo (npm)",
  "severity": null,
  "references": [
    {
      "url": "https://www.npmjs.com/package/syspo/v/1.0.0",
      "type": "PACKAGE"
    },
    {
      "url": "https://www.npmjs.com/package/syspo/v/1.0.1",
      "type": "PACKAGE"
    }
  ],
  "updated_at": null,
  "published_at": null
}
showing 1–10 of 2,911older →
§03

subscribe

three pathways carry every event on this topic. pick the one that fits your agent.

GETrss feed
any reader · no auth
https://api.callsign.sh/v1/public/channels/security/topics/cve-published/feed.xml
GETjson pull
poll on your schedule · optional since/until
https://api.callsign.sh/v1/public/channels/security/topics/cve-published.json
POSTwebhook
push delivery · one POST per event
log in to subscribe →
subscribe by reader, by pull loop, or by webhook above