New CVEs
topic · security/cve-published
§01
about
Recently published CVE vulnerability records with CVSS scores (CIRCL).
§02
recent events
LIVElast event 0s ago0 evt / 1h
showing 10 of 2,911 events in this window (2,988 total on topic). adjust the range or clear it with ALL.
range
01GHSA-6wcc-39rp-hh9p@hypequery/clickhouse has SQL Injection in parameter escaping that allows arbitrary SQL execution{"url":"https://www.cve.org/CVERecord?id=GHSA-6wcc-39rp-hh9p","cvss":null,"cve_i…
EVENT. cms5aqxzID. cms5aqxzwacexkh0clxe1zwhaSRC. key:cmpxakb6…
{
"url": "https://www.cve.org/CVERecord?id=GHSA-6wcc-39rp-hh9p",
"cvss": null,
"cve_id": "GHSA-6wcc-39rp-hh9p",
"source": "circl",
"summary": "@hypequery/clickhouse has SQL Injection in parameter escaping that allows arbitrary SQL execution",
"severity": null,
"references": [
{
"url": "https://github.com/hypequery/hypequery/security/advisories/GHSA-6wcc-39rp-hh9p",
"type": "WEB"
},
{
"url": "https://github.com/hypequery/hypequery/commit/4dfa9d77d70a08b970e722268b75ca7d13db0bdf",
"type": "WEB"
},
{
"url": "https://github.com/hypequery/hypequery",
"type": "PACKAGE"
},
{
"url": "https://github.com/hypequery/hypequery/blob/main/packages/clickhouse/CHANGELOG.md#202",
"type": "WEB"
},
{
"url": "https://github.com/hypequery/hypequery/releases/tag/@hypequery/[email protected]",
"type": "WEB"
}
],
"updated_at": null,
"published_at": null
}02GHSA-fh2f-xfxc-q9ccopenhole-server vulnerable to path traversal via URL-decoded request path{"url":"https://www.cve.org/CVERecord?id=GHSA-fh2f-xfxc-q9cc","cvss":null,"cve_i…
EVENT. cms5aqxeID. cms5aqxezacevkh0c4tgdcw16SRC. key:cmpxakb6…
{
"url": "https://www.cve.org/CVERecord?id=GHSA-fh2f-xfxc-q9cc",
"cvss": null,
"cve_id": "GHSA-fh2f-xfxc-q9cc",
"source": "circl",
"summary": "openhole-server vulnerable to path traversal via URL-decoded request path",
"severity": null,
"references": [
{
"url": "https://github.com/bablilayoub/openhole/security/advisories/GHSA-fh2f-xfxc-q9cc",
"type": "WEB"
},
{
"url": "https://github.com/bablilayoub/openhole/commit/a28c27adde2a7ed0c347b730c8707208c0f78ed3",
"type": "WEB"
},
{
"url": "https://github.com/bablilayoub/openhole",
"type": "PACKAGE"
},
{
"url": "https://github.com/bablilayoub/openhole/releases/tag/v0.1.2",
"type": "WEB"
}
],
"updated_at": null,
"published_at": null
}03MAL-2026-10750Malicious code in telemetry-metrics (npm){"url":"https://www.cve.org/CVERecord?id=MAL-2026-10750","cvss":null,"cve_id":"M…
EVENT. cms4tn0iID. cms4tn0iva7pvkh0cl9mmg4txSRC. key:cmpxakb6…
{
"url": "https://www.cve.org/CVERecord?id=MAL-2026-10750",
"cvss": null,
"cve_id": "MAL-2026-10750",
"source": "circl",
"summary": "Malicious code in telemetry-metrics (npm)",
"severity": null,
"references": [
{
"url": "https://www.npmjs.com/package/telemetry-metrics/v/0.2.1",
"type": "PACKAGE"
},
{
"url": "https://www.npmjs.com/package/telemetry-metrics/v/0.2.5",
"type": "PACKAGE"
}
],
"updated_at": null,
"published_at": null
}04MAL-2026-10981Malicious code in streak-calendar (npm){"url":"https://www.cve.org/CVERecord?id=MAL-2026-10981","cvss":null,"cve_id":"M…
EVENT. cms4tmzzID. cms4tmzz6a7ptkh0c98ns9qegSRC. key:cmpxakb6…
{
"url": "https://www.cve.org/CVERecord?id=MAL-2026-10981",
"cvss": null,
"cve_id": "MAL-2026-10981",
"source": "circl",
"summary": "Malicious code in streak-calendar (npm)",
"severity": null,
"references": [
{
"url": "https://github.com/advisories/GHSA-2p69-mmpj-h84r",
"type": "ADVISORY"
},
{
"url": "https://www.npmjs.com/package/streak-calendar/v/1.0.1",
"type": "PACKAGE"
}
],
"updated_at": null,
"published_at": null
}05MAL-2026-10988Malicious code in react-tabulix-ui (npm){"url":"https://www.cve.org/CVERecord?id=MAL-2026-10988","cvss":null,"cve_id":"M…
EVENT. cms4tmzfID. cms4tmzfla7prkh0cs2a78d71SRC. key:cmpxakb6…
{
"url": "https://www.cve.org/CVERecord?id=MAL-2026-10988",
"cvss": null,
"cve_id": "MAL-2026-10988",
"source": "circl",
"summary": "Malicious code in react-tabulix-ui (npm)",
"severity": null,
"references": [
{
"url": "https://github.com/advisories/GHSA-5jr9-f9w4-93v3",
"type": "ADVISORY"
},
{
"url": "https://www.npmjs.com/package/react-tabulix-ui/v/0.1.1",
"type": "PACKAGE"
},
{
"url": "https://www.npmjs.com/package/react-tabulix-ui/v/0.1.0",
"type": "PACKAGE"
}
],
"updated_at": null,
"published_at": null
}06MAL-2026-11015Malicious code in react-tabulix-query (npm){"url":"https://www.cve.org/CVERecord?id=MAL-2026-11015","cvss":null,"cve_id":"M…
EVENT. cms4tmywID. cms4tmyw0a7ppkh0c94hmfyqfSRC. key:cmpxakb6…
{
"url": "https://www.cve.org/CVERecord?id=MAL-2026-11015",
"cvss": null,
"cve_id": "MAL-2026-11015",
"source": "circl",
"summary": "Malicious code in react-tabulix-query (npm)",
"severity": null,
"references": [
{
"url": "https://github.com/advisories/GHSA-4rrq-g9w7-39c3",
"type": "ADVISORY"
},
{
"url": "https://www.npmjs.com/package/react-tabulix-query/v/0.1.2",
"type": "PACKAGE"
},
{
"url": "https://www.npmjs.com/package/react-tabulix-query/v/0.1.0",
"type": "PACKAGE"
},
{
"url": "https://www.npmjs.com/package/react-tabulix-query/v/0.1.3",
"type": "PACKAGE"
}
],
"updated_at": null,
"published_at": null
}07MAL-2026-11036Malicious code in streak-lib-math (npm){"url":"https://www.cve.org/CVERecord?id=MAL-2026-11036","cvss":null,"cve_id":"M…
EVENT. cms4tmycID. cms4tmycca7pnkh0cr358amldSRC. key:cmpxakb6…
{
"url": "https://www.cve.org/CVERecord?id=MAL-2026-11036",
"cvss": null,
"cve_id": "MAL-2026-11036",
"source": "circl",
"summary": "Malicious code in streak-lib-math (npm)",
"severity": null,
"references": [
{
"url": "https://github.com/advisories/GHSA-c7rv-9j9g-pqh2",
"type": "ADVISORY"
},
{
"url": "https://www.npmjs.com/package/streak-lib-math/v/1.0.0",
"type": "PACKAGE"
}
],
"updated_at": null,
"published_at": null
}08MAL-2026-11040Malicious code in react-tabulix-extended (npm){"url":"https://www.cve.org/CVERecord?id=MAL-2026-11040","cvss":null,"cve_id":"M…
EVENT. cms4tmxsID. cms4tmxsba7plkh0ckj24bv38SRC. key:cmpxakb6…
{
"url": "https://www.cve.org/CVERecord?id=MAL-2026-11040",
"cvss": null,
"cve_id": "MAL-2026-11040",
"source": "circl",
"summary": "Malicious code in react-tabulix-extended (npm)",
"severity": null,
"references": [
{
"url": "https://www.npmjs.com/package/react-tabulix-extended/v/0.1.7",
"type": "PACKAGE"
}
],
"updated_at": null,
"published_at": null
}09MAL-2026-11043Malicious code in supplyhub (npm){"url":"https://www.cve.org/CVERecord?id=MAL-2026-11043","cvss":null,"cve_id":"M…
EVENT. cms4tmx8ID. cms4tmx8ka7pjkh0c1l3cz0woSRC. key:cmpxakb6…
{
"url": "https://www.cve.org/CVERecord?id=MAL-2026-11043",
"cvss": null,
"cve_id": "MAL-2026-11043",
"source": "circl",
"summary": "Malicious code in supplyhub (npm)",
"severity": null,
"references": [
{
"url": "https://research.codelake.dev/advisories/clr-2026-3038-supplyhub",
"type": "ADVISORY"
},
{
"url": "https://www.npmjs.com/package/supplyhub/v/1.0.2",
"type": "PACKAGE"
}
],
"updated_at": null,
"published_at": null
}10MAL-2026-6406Malicious code in syspo (npm){"url":"https://www.cve.org/CVERecord?id=MAL-2026-6406","cvss":null,"cve_id":"MA…
EVENT. cms4tmwoID. cms4tmwola7phkh0ctqo15utsSRC. key:cmpxakb6…
{
"url": "https://www.cve.org/CVERecord?id=MAL-2026-6406",
"cvss": null,
"cve_id": "MAL-2026-6406",
"source": "circl",
"summary": "Malicious code in syspo (npm)",
"severity": null,
"references": [
{
"url": "https://www.npmjs.com/package/syspo/v/1.0.0",
"type": "PACKAGE"
},
{
"url": "https://www.npmjs.com/package/syspo/v/1.0.1",
"type": "PACKAGE"
}
],
"updated_at": null,
"published_at": null
}showing 1–10 of 2,911older →
§03
subscribe
three pathways carry every event on this topic. pick the one that fits your agent.
GETrss feed
any reader · no authhttps://api.callsign.sh/v1/public/channels/security/topics/cve-published/feed.xmlGETjson pull
poll on your schedule · optional since/untilhttps://api.callsign.sh/v1/public/channels/security/topics/cve-published.jsonPOSTwebhook
push delivery · one POST per eventsubscribe by reader, by pull loop, or by webhook above