🧰

Developer Tooling

slug: developer-tooling

🛡 Related vulnerabilities 31

ID Title
CVE-2026-78677 GitPython before 3.1.59 omits --separate-git-dir from unsafe_git_clone_options, allowing...
CVE-2026-78209 exceljs-hardened versions before 5.0.0 fail to neutralize leading equals, plus, minus, or at...
CVE-2026-78136 chirpmyradio CHIRP before 39178db allows eval injection via crafted CSV data. This occurs in...
CVE-2026-62960 Git for Windows is the Windows port of Git. Prior to 2.55.0.windows.4, a malicious remote Git server can advertise a bundle URI that reaches transport_get_remote_bundle_uri(), fetch_bundle_uri_interna...
CVE-2026-73224 electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3.15.120, electerm allows a malicious FTP or SFTP server to execute arbitrary commands when a user do...
CVE-2026-73226 electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3.15.186, electerm allows an authenticated WebSocket client to invoke unintended internal functions t...
CVE-2026-73222 Claude Code Templates is a CLI tool for configuring and monitoring Claude Code. Prior to 1.29.4, the Claude Code Studio server launched by the --studio option in cli-tool/src/sandbox-server.js binds t...
CVE-2026-48120 Kakoune is a code editor. Prior to version 2026.05.21, the bundled, enabled by default, `autorestore.kak` script can be exploited by malicious backup files leading to arbitrary kakoune and shell comma...
CVE-2026-66036 FFmpeg through 8.1.2, fixed in commit 5d7112c, contains a heap out-of-bounds write vulnerability...
CVE-2026-58049 FFmpeg's RASC video decoder (decode_dlta in libavcodec/rasc.c) performs 32-bit reads and writes...
CVE-2026-47964 DNG SDK versions 1.7.1 2536 and earlier are affected by a Heap-based Buffer Overflow...
CVE-2026-47908 Dreamweaver Desktop versions 21.7 and earlier are affected by an Access of Uninitialized Pointer...
CVE-2026-49366 In JetBrains IntelliJ IDEA before 2026.1.1 command injection was possible via filename completion
CVE-2026-49367 In JetBrains IntelliJ IDEA before 2026.1.1 command execution was possible via the guest user account
CVE-2026-42302 Vulnerability in openai-sdk (CVE-2026-42302)
CVE-2026-41588 Vulnerability in timing-attack (CVE-2026-41588)
CVE-2026-41507 Code Injection in remote (CVE-2026-41507)
CVE-2026-43944 Vulnerability in electerm (CVE-2026-43944)
CVE-2026-41500 Command Injection in electerm-project (CVE-2026-41500)
CVE-2025-63704 Vulnerability in prototype-pollution (CVE-2025-63704)
CVE-2025-63706 Code Injection in npm (CVE-2025-63706)
CVE-2026-34084 Unsafe Deserialization in phpoffice/phpspreadsheet (CVE-2026-34084)
CVE-2026-38431 Code Injection in frappe (CVE-2026-38431)
CVE-2026-26956 Vulnerability in vm2-project (CVE-2026-26956)
CVE-2026-24118 Code Injection in vm2-project (CVE-2026-24118)
CVE-2026-24781 Code Injection in vm2-project (CVE-2026-24781)
CVE-2012-1854 KEV [KEV] Vulnerability in Microsoft visual-basic-for-applications-vba (CVE-2012-1854)
CVE-2026-32146 Improper Path Validation in Git Dependency Handling Allows Arbitrary File System Modification
CVE-2020-37208 SpotFTP 3.0.0.0 contains a buffer overflow vulnerability in the registration key input field that allows attackers to crash the application. Attackers can generate a 1000-character payload and paste i...
CVE-2025-69262 pnpm is a package manager. Versions 6.25.0 through 10.26.2 have a Command Injection vulnerability when using environment variable substitution in .npmrc configuration files with tokenHelper settings....

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →