Sep 02 GHSA-g7vv-4mjj-6fgm (alchemy_cms): Account Takeover & Privilege-Escalation To Admin via Stored XSS in Menu Node Name Rendered in Page Properties Configure Dialog posted in •
Sep 02 GHSA-4qhx-6wrv-5hg2 (alchemy_cms): Account Takeover & Privilege-Escalation To Admin via Stored XSS in Menu Node Name Rendered in Admin Configure Dialog Page Content posted in •
Aug 27 CVE-2026-81097 (rails-mcp-server): The execute_ruby tool is documented as a read-only Ruby sandbox posted in •
Aug 27 CVE-2026-80212 (resolv): CVE-2026-80212 - Memory exhaustion through malicious DNS responses posted in •
Aug 18 CVE-2026-55107 (kobako): kobako Sandbox Escape - guest eval reaches host RCE via method_missing → public_send (any bound Service) posted in •
Aug 17 GHSA-rmxg-5p3r-j6hh (graphql): Unsafe Marshal deserialization in the parser cache can lead to arbitrary Ruby code execution posted in •
Aug 12 CVE-2026-73330 (camaleon_cms): CamaleonCMS 2.9.1 Server-Side Template Injection via test_email Action posted in •
Aug 11 GHSA-mwm8-39rw-8826 (sqlite3): Use-After-Free in SQLite Aggregate Arguments in Heap-Allocated Argument Array posted in •