Known Vulnerabilities for D8s-lists by Democritus
Listed below are 1 of the newest known vulnerabilities associated with "D8s-lists" by "Democritus".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-65911 json | In DOMPurify through 3.3.3, function predicates supplied via ADD_ATTR or ADD_TAGS to DOMPurify.sanitize() persist in internal... | Not Provided | 2026-07-23 | 2026-07-23 |
| CVE-2026-65902 json | DOMPurify before 3.4.7 (affected versions <= 3.4.5) passes direct references to the module-level DEFAULT_ALLOWED_TAGS and DEF... | Not Provided | 2026-07-23 | 2026-07-23 |
| CVE-2026-64142 json | In the Linux kernel, the following vulnerability has been resolved: ksmbd: close durable scavenger races against m_fp_list l... | Not Provided | 2026-07-19 | 2026-07-20 |
| CVE-2026-63990 json | In the Linux kernel, the following vulnerability has been resolved: bonding: refuse to enslave CAN devices syzbot reported ... | Not Provided | 2026-07-19 | 2026-07-19 |
| CVE-2026-63736 json | SurrealDB before 3.2.0 contains a server-side request forgery vulnerability in the JWKS fetcher that validates only the URL h... | Not Provided | 2026-07-20 | 2026-07-20 |
| CVE-2026-61428 json | PraisonAI AgentMail versions before 4.6.78 lack signature verification in webhook mode, allowing unauthenticated attackers to... | Not Provided | 2026-07-11 | 2026-07-13 |
| CVE-2026-59213 json | Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.6.27 before 0.10.0, get_all_mode... | Not Provided | 2026-07-09 | 2026-07-09 |
| CVE-2026-57960 json | Hi.Events through 1.9.0 public check-in list endpoints use short_id as sole access control, allowing unauthenticated access t... | Not Provided | 2026-06-29 | 2026-07-14 |
| CVE-2026-57081 json | Net::BitTorrent versions through 2.1.0 for Perl allow remote memory exhaustion via deeply nested bencoded input. bdecode rec... | Not Provided | 2026-06-30 | 2026-07-20 |
| CVE-2026-55990 json | In NLnet Labs Unbound 1.7.0 up to and including 1.25.1, when the 'dnscrypt:' clause lists more 'dnscrypt-provider-cert:' file... | Not Provided | 2026-07-22 | 2026-07-22 |