New CVEs
topic · security/cve-published
§01
about
Recently published CVE vulnerability records with CVSS scores (CIRCL).
§02
recent events
LIVElast event 0s ago0 evt / 1h
showing 10 of 2,920 events in this window (2,988 total on topic). adjust the range or clear it with ALL.
range
01GHSA-h39x-gxcq-jm2vGHSA-h39x-gxcq-jm2v{"url":"https://www.cve.org/CVERecord?id=GHSA-h39x-gxcq-jm2v","cvss":null,"cve_i…
EVENT. cms6qbifID. cms6qbif1apvbkh0ci2b7raoySRC. key:cmpxakb6…
{
"url": "https://www.cve.org/CVERecord?id=GHSA-h39x-gxcq-jm2v",
"cvss": null,
"cve_id": "GHSA-h39x-gxcq-jm2v",
"source": "circl",
"summary": null,
"severity": null,
"references": [
{
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-50782",
"type": "ADVISORY"
},
{
"url": "https://github.com/dihe123/CNVD-Jinher-OA-XXE/blob/main/README.md",
"type": "WEB"
},
{
"url": "https://github.com/dihe123/CNVD-Jinher-OA-XXE/tree/main",
"type": "WEB"
}
],
"updated_at": null,
"published_at": null
}02GHSA-hhjf-qv52-vp59GHSA-hhjf-qv52-vp59{"url":"https://www.cve.org/CVERecord?id=GHSA-hhjf-qv52-vp59","cvss":null,"cve_i…
EVENT. cms6qbhuID. cms6qbhutapv9kh0chiv08mbkSRC. key:cmpxakb6…
{
"url": "https://www.cve.org/CVERecord?id=GHSA-hhjf-qv52-vp59",
"cvss": null,
"cve_id": "GHSA-hhjf-qv52-vp59",
"source": "circl",
"summary": null,
"severity": null,
"references": [
{
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-13309",
"type": "ADVISORY"
},
{
"url": "https://www.zerodayinitiative.com/advisories/ZDI-26-435",
"type": "WEB"
}
],
"updated_at": null,
"published_at": null
}03GHSA-mp9m-rq8w-3xm6GHSA-mp9m-rq8w-3xm6{"url":"https://www.cve.org/CVERecord?id=GHSA-mp9m-rq8w-3xm6","cvss":null,"cve_i…
EVENT. cms6qbh9ID. cms6qbh9wapv7kh0cl6x6hqjySRC. key:cmpxakb6…
{
"url": "https://www.cve.org/CVERecord?id=GHSA-mp9m-rq8w-3xm6",
"cvss": null,
"cve_id": "GHSA-mp9m-rq8w-3xm6",
"source": "circl",
"summary": null,
"severity": null,
"references": [
{
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-13305",
"type": "ADVISORY"
},
{
"url": "https://www.zerodayinitiative.com/advisories/ZDI-26-433",
"type": "WEB"
}
],
"updated_at": null,
"published_at": null
}04GHSA-q4xr-8q49-vvhjGHSA-q4xr-8q49-vvhj{"url":"https://www.cve.org/CVERecord?id=GHSA-q4xr-8q49-vvhj","cvss":null,"cve_i…
EVENT. cms6qbgpID. cms6qbgpfapv5kh0cozs3px7oSRC. key:cmpxakb6…
{
"url": "https://www.cve.org/CVERecord?id=GHSA-q4xr-8q49-vvhj",
"cvss": null,
"cve_id": "GHSA-q4xr-8q49-vvhj",
"source": "circl",
"summary": null,
"severity": null,
"references": [
{
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-65340",
"type": "ADVISORY"
},
{
"url": "https://github.com/um-dsp/TaintRadar/blob/main/sql_injection_cves/hospitalmanagementsystemproject/20250811-hospital-management-system-betweendates-detailsreports.php-fromdate-sqli/20250811-hospital-management-system-betweendates-detailsreports.php-fromdate-sqli.md#injection-techniques-as-identified-by-sqlmap",
"type": "WEB"
}
],
"updated_at": null,
"published_at": null
}05RLSA-2026:46394Important: go-fdo-client security update{"url":"https://www.cve.org/CVERecord?id=RLSA-2026:46394","cvss":null,"cve_id":"…
EVENT. cms5ryf7ID. cms5ryf71agrjkh0col5tjolwSRC. key:cmpxakb6…
{
"url": "https://www.cve.org/CVERecord?id=RLSA-2026:46394",
"cvss": null,
"cve_id": "RLSA-2026:46394",
"source": "circl",
"summary": "Important: go-fdo-client security update",
"severity": null,
"references": [
{
"url": "https://errata.rockylinux.org/RLSA-2026:46394",
"type": "ADVISORY"
},
{
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2484207",
"type": "REPORT"
}
],
"updated_at": null,
"published_at": null
}06RLSA-2026:46395Important: go-fdo-server security update{"url":"https://www.cve.org/CVERecord?id=RLSA-2026:46395","cvss":null,"cve_id":"…
EVENT. cms5ryenID. cms5ryenmagrhkh0co3t4izkuSRC. key:cmpxakb6…
{
"url": "https://www.cve.org/CVERecord?id=RLSA-2026:46395",
"cvss": null,
"cve_id": "RLSA-2026:46395",
"source": "circl",
"summary": "Important: go-fdo-server security update",
"severity": null,
"references": [
{
"url": "https://errata.rockylinux.org/RLSA-2026:46395",
"type": "ADVISORY"
},
{
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2480756",
"type": "REPORT"
},
{
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2484207",
"type": "REPORT"
}
],
"updated_at": null,
"published_at": null
}07RLSA-2026:46398Important: libreswan security update{"url":"https://www.cve.org/CVERecord?id=RLSA-2026:46398","cvss":null,"cve_id":"…
EVENT. cms5rye3ID. cms5rye3uagrfkh0ch109y4spSRC. key:cmpxakb6…
{
"url": "https://www.cve.org/CVERecord?id=RLSA-2026:46398",
"cvss": null,
"cve_id": "RLSA-2026:46398",
"source": "circl",
"summary": "Important: libreswan security update",
"severity": null,
"references": [
{
"url": "https://errata.rockylinux.org/RLSA-2026:46398",
"type": "ADVISORY"
},
{
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2494147",
"type": "REPORT"
},
{
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2501764",
"type": "REPORT"
},
{
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2494149",
"type": "REPORT"
},
{
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2494148",
"type": "REPORT"
}
],
"updated_at": null,
"published_at": null
}08GHSA-wg2q-39h6-66x9goshs has a Path Traversal issue{"url":"https://www.cve.org/CVERecord?id=GHSA-wg2q-39h6-66x9","cvss":null,"cve_i…
EVENT. cms5aqz2ID. cms5aqz2tacf1kh0cjabclsvxSRC. key:cmpxakb6…
{
"url": "https://www.cve.org/CVERecord?id=GHSA-wg2q-39h6-66x9",
"cvss": null,
"cve_id": "GHSA-wg2q-39h6-66x9",
"source": "circl",
"summary": "goshs has a Path Traversal issue",
"severity": null,
"references": [
{
"url": "https://github.com/goshs-labs/goshs/security/advisories/GHSA-wg2q-39h6-66x9",
"type": "WEB"
},
{
"url": "https://github.com/goshs-labs/goshs/commit/f3ef599e409151d1380866e47de8b1afb0bb54fa",
"type": "WEB"
},
{
"url": "https://github.com/goshs-labs/goshs",
"type": "PACKAGE"
}
],
"updated_at": null,
"published_at": null
}09GHSA-whmm-qj9r-wvr2td has pre-auth denial of service via unbounded memory allocation in proto.UnencryptedMessage.Decode{"url":"https://www.cve.org/CVERecord?id=GHSA-whmm-qj9r-wvr2","cvss":null,"cve_i…
EVENT. cms5aqyjID. cms5aqyj6acezkh0cy7s2k4o3SRC. key:cmpxakb6…
{
"url": "https://www.cve.org/CVERecord?id=GHSA-whmm-qj9r-wvr2",
"cvss": null,
"cve_id": "GHSA-whmm-qj9r-wvr2",
"source": "circl",
"summary": "td has pre-auth denial of service via unbounded memory allocation in proto.UnencryptedMessage.Decode",
"severity": null,
"references": [
{
"url": "https://github.com/gotd/td/security/advisories/GHSA-whmm-qj9r-wvr2",
"type": "WEB"
},
{
"url": "https://github.com/gotd/td/issues/1711",
"type": "WEB"
},
{
"url": "https://github.com/gotd/td/commit/9d5d1f31ea5022d9798d84ccce15de2e91ba6baa",
"type": "WEB"
},
{
"url": "https://github.com/gotd/td",
"type": "PACKAGE"
},
{
"url": "https://github.com/gotd/td/releases/tag/v0.145.1",
"type": "WEB"
}
],
"updated_at": null,
"published_at": null
}10GHSA-6wcc-39rp-hh9p@hypequery/clickhouse has SQL Injection in parameter escaping that allows arbitrary SQL execution{"url":"https://www.cve.org/CVERecord?id=GHSA-6wcc-39rp-hh9p","cvss":null,"cve_i…
EVENT. cms5aqxzID. cms5aqxzwacexkh0clxe1zwhaSRC. key:cmpxakb6…
{
"url": "https://www.cve.org/CVERecord?id=GHSA-6wcc-39rp-hh9p",
"cvss": null,
"cve_id": "GHSA-6wcc-39rp-hh9p",
"source": "circl",
"summary": "@hypequery/clickhouse has SQL Injection in parameter escaping that allows arbitrary SQL execution",
"severity": null,
"references": [
{
"url": "https://github.com/hypequery/hypequery/security/advisories/GHSA-6wcc-39rp-hh9p",
"type": "WEB"
},
{
"url": "https://github.com/hypequery/hypequery/commit/4dfa9d77d70a08b970e722268b75ca7d13db0bdf",
"type": "WEB"
},
{
"url": "https://github.com/hypequery/hypequery",
"type": "PACKAGE"
},
{
"url": "https://github.com/hypequery/hypequery/blob/main/packages/clickhouse/CHANGELOG.md#202",
"type": "WEB"
},
{
"url": "https://github.com/hypequery/hypequery/releases/tag/@hypequery/[email protected]",
"type": "WEB"
}
],
"updated_at": null,
"published_at": null
}showing 1–10 of 2,920older →
§03
subscribe
three pathways carry every event on this topic. pick the one that fits your agent.
GETrss feed
any reader · no authhttps://api.callsign.sh/v1/public/channels/security/topics/cve-published/feed.xmlGETjson pull
poll on your schedule · optional since/untilhttps://api.callsign.sh/v1/public/channels/security/topics/cve-published.jsonPOSTwebhook
push delivery · one POST per eventsubscribe by reader, by pull loop, or by webhook above