Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-52877 |
|
Vulnerability in CVE-2026-52877 (CVE-2026-52877)
vulnerability in CVE-2026-52877 (CVE-2026-52877). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-53633 |
|
Vulnerability in @vitest/browser (CVE-2026-53633)
vulnerability in @vitest/browser (CVE-2026-53633). Successful exploitation can lead to full system takeover. Exploitable via ``browser.api.allowWrite``. Mitigation: upgrade to `3.2.5` or later.
|
| CVE-2026-49993 |
|
Vulnerability in @nuxt/webpack-builder (CVE-2026-49993)
vulnerability in @nuxt/webpack-builder (CVE-2026-49993). Confidential information can be exposed externally. Exploitable via ``Origin``. Mitigation: upgrade to `3.21.7` or later.
|
| CVE-2026-47899 |
|
Vulnerability in CVE-2026-47899 (CVE-2026-47899)
vulnerability in CVE-2026-47899 (CVE-2026-47899). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-44698 |
|
Code Injection in CVE-2026-44698 (CVE-2026-44698)
code injection in CVE-2026-44698 (CVE-2026-44698). Successful exploitation can lead to full system takeover. Exploitable via ``window.externalApp``. Mitigation: upgrade to `2026.4.1` or later.
|
| CVE-2026-45805 |
|
Vulnerability in @penpot/mcp (CVE-2026-45805)
vulnerability in @penpot/mcp (CVE-2026-45805). Successful exploitation can lead to full system takeover. Exploitable via ``ReplServer``. Mitigation: upgrade to `2.15.0` or later.
|
| CVE-2026-45670 |
|
Vulnerability in @nuxt/rspack-builder (CVE-2026-45670)
vulnerability in @nuxt/rspack-builder (CVE-2026-45670). Risk of unauthorized operations or information disclosure. Exploitable via ``script.src``. Mitigation: upgrade to `4.4.6` or later.
|
| CVE-2026-44836 |
|
Vulnerability in view_component (CVE-2026-44836)
vulnerability in view_component (CVE-2026-44836). Confidential information can be exposed externally. Exploitable via `GET /rails/view_components/my_component/render_with_template`. Mitigation: upgrade to `4.9.0` or later.
|
| CVE-2026-24118 |
|
Code Injection in vm2-project (CVE-2026-24118)
code injection in vm2-project (CVE-2026-24118). Successful exploitation can lead to full system takeover. Exploitable via ``__lookupGetter__``.
|
| CVE-2024-25675 |
|
Vulnerability in misp-project (CVE-2024-25675)
vulnerability in misp-project (CVE-2024-25675). Successful exploitation can lead to full system takeover.
|