Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
MAL-2026-6
  • PyPI/ziphash
Malicious code in ziphash (PyPI) 6 hours ago
  • No fix available
MAL-2026-5
  • PyPI/queryservice-client
Malicious code in queryservice-client (PyPI) 9 hours ago
  • No fix available
CVE-2025-69203
  • github.com/signalk/signalk-server
Signal K Server Vulnerable to Access Request Spoofing 10 hours ago
  • Fix available
  • Severity - 6.3 (Medium)
CVE-2025-68619
  • github.com/signalk/signalk-server
Signal K Server Vulnerable to Remote Code Execution via Malicious npm Package 10 hours ago
  • Fix available
  • Severity - 7.3 (High)
CVE-2025-68620
  • github.com/signalk/signalk-server
Signal K Server vulnerable to JWT Token Theft via WebSocket Enumeration and Unauthenticated Polling 10 hours ago
  • Fix available
  • Severity - 9.1 (Critical)
CVE-2025-68273
  • github.com/signalk/signalk-server
Signal K Server Vulnerable to Unauthenticated Information Disclosure via Exposed Endpoints 10 hours ago
  • Fix available
  • Severity - 5.3 (Medium)
CVE-2025-68272
  • github.com/signalk/signalk-server
Signal K Server Vulnerable to Denial of Service via Unrestricted Access Request Flooding 10 hours ago
  • Fix available
  • Severity - 7.5 (High)
CVE-2025-66398
  • github.com/signalk/signalk-server
Signal K Server has Unauthenticated State Pollution leading to Remote Code Execution (RCE) 10 hours ago
  • Fix available
  • Severity - 9.6 (Critical)
MAL-2026-4
  • npm/rules-playground
Malicious code in rules-playground (npm) 11 hours ago
  • No fix available
MAL-2026-3
  • npm/rules-deployer
Malicious code in rules-deployer (npm) 11 hours ago
  • No fix available
MAL-2026-2
  • npm/common-cli-utils
Malicious code in common-cli-utils (npm) 11 hours ago
  • No fix available
CVE-2025-66023
  • github.com/nanomq/nanonng
NanoMQ has Use-After-Free of malformed bridging message 13 hours ago
  • Fix available
  • Severity - 6.9 (Medium)
ECHO-4b45-6ff3-bbe1
  • Echo/iputils
See record for full details 14 hours ago
  • No fix available
ECHO-df75-75a7-da98
  • Echo/rsync
See record for full details 14 hours ago
  • No fix available
ECHO-cf16-1305-6c35
  • Echo/postgresql-common
See record for full details 14 hours ago
  • Fix available
ECHO-4017-b212-426e
  • Echo/postgresql-common
See record for full details 14 hours ago
  • Fix available