Latest CVEs

Generated 27 Aug 2026 14:23 UTC
Dataset 2026-08-24.b03ba7eb
IDPackagesSummaryPublished ↓
CVE-2026-54133mtdowling/jmespath.phpCompilerRuntime code injection via unescaped function names18 Aug
CVE-2026-67434league/commonmark, squizlabs/php_codesnifferleague/commonmark: Denial of service via colliding heading slugs6 Aug
CVE-2026-71488league/commonmarkleague/commonmark: Quadratic-time denial of service when parsing crafted Markdown6 Aug
CVE-2026-71478league/commonmarkleague/commonmark: AttributesExtension href/src unsafe-link filter bypass via embedded...6 Aug
CVE-2026-69246guzzlehttp/guzzleGuzzle: Noncanonical host can bypass host-based checks3 Aug
CVE-2026-69245guzzlehttp/guzzleGuzzle: Noncanonical cookie domain keeps subdomain scope3 Aug
CVE-2026-65954phpcsstandards/phpcsutilsArbitrary code execution27 Jul
CVE-2026-59882guzzlehttp/psr7guzzlehttp/psr7: Host Confusion via Weak URI Host Validation21 Jul
CVE-2026-67354guzzlehttp/guzzleGuzzle: URI fragments disclosed in redirect Referer headers20 Jul
CVE-2026-67353guzzlehttp/guzzleGuzzle: Unbounded response cookies risk denial of service20 Jul