| CVE-2026-81702 | 9.8 | — | — | — | jahlives / openssl encrypt | openssl_encrypt before 1.4.9 fails to re-derive and validate fingerprints when loading identities from identity.js | 9d ago |
| CVE-2026-81701 | 9.8 | — | — | — | jahlives / openssl encrypt | openssl_encrypt versions before 1.4.9 use a denylist to identify trusted built-in plugins, allowing unsigned plugi | 9d ago |
| CVE-2026-81700 | 9.8 | — | — | — | jahlives / openssl encrypt | openssl_encrypt versions before 1.4.9 contain a signature verification vulnerability in gpg_runner.verify_detached | 9d ago |
| CVE-2026-74901 | 9.8 | — | — | — | jahlives / openssl encrypt | openssl_encrypt versions before 1.4.0 contain an authentication bypass vulnerability in pqc.py where AES-GCM decry | 19d ago |
| CVE-2026-74900 | 9.8 | — | — | — | jahlives / openssl encrypt | openssl_encrypt versions before 1.4.0 contain a critical vulnerability in pqc.py where KEM decapsulation failures | 19d ago |
| CVE-2026-74899 | 9.8 | — | — | — | jahlives / openssl encrypt | openssl_encrypt versions before 1.4.0 contain a sandbox escape vulnerability in IsolatedPluginExecutor that expose | 19d ago |
| CVE-2026-74896 | 9.8 | — | — | — | jahlives / openssl encrypt | openssl_encrypt versions before 1.4.0 contain a sandbox escape vulnerability in the DangerousPatternVisitor AST an | 19d ago |
| CVE-2026-74895 | 9.8 | — | — | — | jahlives / openssl encrypt | openssl_encrypt versions before 1.4.0 fail to apply sandbox restrictions in the default process isolation mode for | 19d ago |
| CVE-2026-74894 | 9.8 | — | — | — | jahlives / openssl encrypt | openssl_encrypt before 1.4.0 contains an authentication bypass vulnerability in the verify_api_token function that | 19d ago |
| CVE-2026-74891 | 9.8 | — | — | — | jahlives / openssl encrypt | openssl_encrypt versions before 1.4.0 contain hardcoded database credentials in standalone server configuration fi | 19d ago |
| CVE-2026-74889 | 9.8 | — | — | — | jahlives / openssl encrypt | openssl_encrypt versions before 1.4.0 use HKDF with no salt and static info parameter in key normalization functio | 19d ago |
| CVE-2026-74886 | 9.8 | — | — | — | jahlives / openssl encrypt | openssl_encrypt versions before 1.4.0 contain a plugin sandbox bypass vulnerability where the PluginImportGuard bl | 19d ago |
| CVE-2026-74880 | 9.8 | — | — | — | jahlives / openssl encrypt | openssl_encrypt versions before 1.4.0 accept refresh tokens as URL query parameters in keyserver and telemetry ser | 19d ago |
| CVE-2026-74878 | 9.8 | — | — | — | jahlives / openssl encrypt | openssl_encrypt versions before 1.4.0 use an in-memory rate limiter for TOTP brute-force protection that is not sh | 19d ago |
| CVE-2026-74876 | 9.8 | — | — | — | jahlives / openssl encrypt | openssl_encrypt versions before 1.4.0 contain a vulnerability in PublicKeyBundle.from_dict() that creates key bund | 19d ago |
| CVE-2026-74875 | 9.8 | — | — | — | jahlives / openssl encrypt | openssl_encrypt versions before 1.4.0 silently skip JSON schema validation when the jsonschema library is not inst | 19d ago |
| CVE-2026-74872 | 9.8 | — | — | — | jahlives / openssl encrypt | openssl_encrypt versions before 1.4.0 contain an arbitrary code execution vulnerability in the Whirlpool hash impl | 19d ago |