Vulnerabilities
Summary — last 7 days
New vulnerabilities2,709▼ 126 vs. last week
Critical / high1,231▼ 312 vs. last week
New active exploitation (KEV)6▼ 1 vs. last week
Unscored (no CVSS)257▲ 221 vs. last week
3 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Analyzed | Critical (9.6) | 1.1% | ⚠ Active exploitation💥 PoC | Tanstack/arktype-adapterTanstack/eslint-plugin-routerTanstack/eslint-plugin-startTanstack/history+167 | 5/12/2026 | 6/17/2026 | On 2026-05-11, between approximately 19:20 and 19:26 UTC, 84 malicious versions across 42 @tanstack/* packages were published to the npm registry. The publishes were authenticated via the legitimate GitHub Actions OIDC trusted-publisher binding for TanStack/router, but the publish workflow itself was not modified. The… | |
| Modified | Critical (9.3) | 1.3% | — | Python-recipe-database Project Python-recipe-database | 7/11/2022 | 6/17/2026 | The JustAnotherSoftwareDeveloper/Python-Recipe-Database repository through 2021-03-31 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. | |
| Modified | Medium (4.3) | 1.3% | — | Adventia E-data | 3/29/2005 | 6/16/2026 | Cross-site scripting (XSS) vulnerability in Adventia E-Data 2.0 allows remote attackers to inject arbitrary web script or HTML via a query keyword. |