Vulnerabilities
Summary — last 7 days
New vulnerabilities2,806▲ 5 vs. last week
Critical / high1,465▲ 246 vs. last week
New active exploitation (KEV)5▼ 5 vs. last week
Unscored (no CVSS)77▼ 441 vs. last week
1 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Modified | Low (2.7) | 0.63% | — | Kpdecker Jsdiff | 1/22/2026 | 7/15/2026 | jsdiff is a JavaScript text differencing implementation. Prior to versions 8.0.3, 5.2.2, 4.0.4, and 3.5.1, attempting to parse a patch whose filename headers contain the line break characters `\r`, `\u2028`, or `\u2029` can cause the `parsePatch` method to enter an infinite loop. It then consumes memory without limit… |