🔓 VULNERABILITIES & CVEs
-
CVE-2026-16206 in django-oauth-toolkit affects OAuth2 token validation — CVSS 6.3 A vulnerability in django-oauth-toolkit's oauth2_validators.py _load_id_token function could cause session-related security issues.
- detail: Affects OAuth2 token validation in django-oauth-toolkit.
- detail: Moderate severity, CVSS 6.3.
-
CVE-2026-16204 in zevorn rt-claw Telegram-to-AI Tool Execution Flow — CVSS 6.3 An issue in the script.c tool_run_script_ex component may allow unauthorized script execution.
- detail: Affects zevorn rt-claw Telegram-to-AI tool.
- detail: Moderate severity, CVSS 6.3.
-
CVE-2026-16205 Pluck CMS Albums XSS vulnerability — CVSS 2.4 Cross-site scripting via albums.admin.php htmlspecialchars_decode function in Pluck CMS Albums.
- detail: Low severity, CVSS 2.4.
-
CVE-2026-16211 in allegro Hostname Allocation A flaw in assets.py AssetLastHostname.increment_hostname related to hostname allocation.
- detail: No CVSS score provided.
-
CVE-2026-16210 in newpanjing simpleui AjaxAdmin endpoint Missing authentication in AJAX Endpoint admin.py self.get_action.
- detail: No CVSS score provided.
-
CVE-2026-16209 in Gerapy Project Upload Endpoint Missing authentication vulnerability in views.py upload endpoint.
- detail: No CVSS score provided.
-
CVE-2026-16208 in django-tastypie throttle.py race condition Race condition flaw in CacheDBThrottle.
- detail: No CVSS score provided.
-
CVE-2026-16207 in django-tastypie authentication.py ApiKeyAuthentication get request method with potential issue.
- detail: No CVSS score provided.