CVE watch
Every disclosure pulled from the NVD feed, filterable by severity.
CVE-2026-78208 published: exceljs-hardened before 5.0.0 contains a path traversal vulnerability in the Workbook.addImage() function that fails to validate file pat...
View full advisory →CVE-2026-78209 published: exceljs-hardened versions before 5.0.0 fail to neutralize leading equals, plus, minus, or at signs in cell values written to CSV output. ...
View full advisory →CVE-2026-78161 published: A vulnerability was found in warmcat libwebsockets 4.5.0. Impacted is the function report_raw_cbor of the file lib/misc/lecp.c of the com...
View full advisory →CVE-2026-78203 published: Ghostwriter before 7.1.2 fails to validate template ownership in the report template swap endpoint, allowing attackers to attach client-s...
View full advisory →CVE-2026-78206 published: exceljs-hardened before 5.0.0 decompresses all entries from supplied xlsx archives into memory without limits on entry size, total size, ...
View full advisory →