Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

Filtering: Group: package-ecosystems Clear
ID Title
CVE-2026-79658 Vulnerability in dos (CVE-2026-79658)
vulnerability in dos (CVE-2026-79658). Risk of unauthorized operations or information disclosure.
CVE-2026-64679 Path Traversal in github.com/runatlantis/atlantis (CVE-2026-64679)
path traversal in github.com/runatlantis/atlantis (CVE-2026-64679). Data can be tampered with by attackers. Exploitable via ``workspace``. Mitigation: upgrade to `0.45.0` or later.
CVE-2026-46603 Vulnerability in dos (CVE-2026-46603)
vulnerability in dos (CVE-2026-46603). Risk of unauthorized operations or information disclosure.
CVE-2026-56865 Vulnerability in CVE-2026-56865 (CVE-2026-56865)
vulnerability in CVE-2026-56865 (CVE-2026-56865). Successful exploitation can lead to full system takeover.
CVE-2026-73654 Trigger.dev: Prototype pollution via run metadata operations → process-wide cross-tenant DoS
Trigger.dev: Prototype pollution via run metadata operations → process-wide cross-tenant DoS
CVE-2026-71272 Memos' webhook dispatch function safeDialContext() (internal/webhook/webhook.go) resolves the...
Memos' webhook dispatch function safeDialContext() (internal/webhook/webhook.go) resolves the...
CVE-2026-71271 Memos' webhook URL validation, isReservedIP() (internal/webhook/validate.go), checks a candidate...
Memos' webhook URL validation, isReservedIP() (internal/webhook/validate.go), checks a candidate...
CVE-2026-71235 Code Injection in ssrf (CVE-2026-71235)
code injection in ssrf (CVE-2026-71235). Successful exploitation can lead to full system takeover.
CVE-2026-71206 Shiori's CheckToken function (internal/domains/auth.go) validates only the JWT's HMAC signature...
Shiori's CheckToken function (internal/domains/auth.go) validates only the JWT's HMAC signature...
CVE-2026-13346 Vulnerability in pypa (CVE-2026-13346)
vulnerability in pypa (CVE-2026-13346). Data can be tampered with by attackers.
CVE-2026-42505 Vulnerability in golang (CVE-2026-42505)
vulnerability in golang (CVE-2026-42505). Risk of unauthorized operations or information disclosure.
CVE-2026-39822 Vulnerability in golang (CVE-2026-39822)
vulnerability in golang (CVE-2026-39822). Successful exploitation can lead to full system takeover.
CVE-2026-50138 Vulnerability in goshs.de/goshs/v2 (CVE-2026-50138)
vulnerability in goshs.de/goshs/v2 (CVE-2026-50138). Confidential information can be exposed externally. Exploitable via ``goshs``. Mitigation: upgrade to `2.1.0` or later.
CVE-2026-14363 SQL Injection in sqli (CVE-2026-14363)
SQL injection in sqli (CVE-2026-14363). Successful exploitation can lead to full system takeover.
CVE-2026-58521 SQL Injection in sqli (CVE-2026-58521)
SQL injection in sqli (CVE-2026-58521). Successful exploitation can lead to full system takeover.
CVE-2026-58519 Cross-Site Scripting (XSS) in mediawiki (CVE-2026-58519)
cross-site scripting in mediawiki (CVE-2026-58519). Risk of unauthorized operations or information disclosure.
CVE-2026-13426 Path Traversal in c (CVE-2026-13426)
path traversal in c (CVE-2026-13426). Risk of unauthorized operations or information disclosure.
CVE-2026-52814 Vulnerability in gogs.io/gogs (CVE-2026-52814)
vulnerability in gogs.io/gogs (CVE-2026-52814). Risk of unauthorized operations or information disclosure.
CVE-2023-54365 Vulnerability in traefik (CVE-2023-54365)
vulnerability in traefik (CVE-2023-54365). Risk of unauthorized operations or information disclosure.
CVE-2026-48154 Vulnerability in github.com/pilinux/gorest (CVE-2026-48154)
vulnerability in github.com/pilinux/gorest (CVE-2026-48154). Risk of unauthorized operations or information disclosure. Exploitable via ``InMemorySecret2FA``. Mitigation: upgrade to `1.12.2` or later.
CVE-2026-11400 AWS-JDBC Wrapper: Privilege Escalation in Aurora PostgreSQL instance
AWS-JDBC Wrapper: Privilege Escalation in Aurora PostgreSQL instance
CVE-2026-11401 AWS Advanced Go Wrapper has Privilege Escalation in Aurora PostgreSQL instance
AWS Advanced Go Wrapper has Privilege Escalation in Aurora PostgreSQL instance
CVE-2026-8643 Path Traversal in pip (CVE-2026-8643)
path traversal in pip (CVE-2026-8643). Data can be tampered with by attackers. Mitigation: upgrade to `26.1.2` or later.
CVE-2026-42083 Free5GC PCF: Missing authentication middleware in Npcf_SMPolicyControl allows access to SM policy handlers and disclosure of subscriber SUPI
Free5GC PCF: Missing authentication middleware in Npcf_SMPolicyControl allows access to SM policy handlers and disclosure of subscriber SUPI
CVE-2026-5222 Vulnerability in cargo (CVE-2026-5222)
vulnerability in cargo (CVE-2026-5222). Confidential information can be exposed externally. Exploitable via ``foo``. Mitigation: upgrade to `0.97.0` or later.
CVE-2026-5223 Vulnerability in cargo (CVE-2026-5223)
vulnerability in cargo (CVE-2026-5223). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.97.0` or later.
CVE-2026-45135 Vulnerability in github.com/caddyserver/caddy/v2 (CVE-2026-45135)
vulnerability in github.com/caddyserver/caddy/v2 (CVE-2026-45135). Successful exploitation can lead to full system takeover. Exploitable via ``search.IgnoreCase``. Mitigation: upgrade to `2.11.3` or later.
CVE-2026-45062 Vulnerability in github.com/dunglas/frankenphp (CVE-2026-45062)
vulnerability in github.com/dunglas/frankenphp (CVE-2026-45062). Successful exploitation can lead to full system takeover. Exploitable via ``cgi.go``. Mitigation: upgrade to `1.12.3` or later.
CVE-2026-42072 Vulnerability in graph (CVE-2026-42072)
vulnerability in graph (CVE-2026-42072). Successful exploitation can lead to full system takeover. Exploitable via ``NORNICDB_ADDRESS``.
CVE-2026-38360 Path Traversal in path-traversal (CVE-2026-38360)
path traversal in path-traversal (CVE-2026-38360). Successful exploitation can lead to full system takeover.
CVE-2026-41507 Code Injection in remote (CVE-2026-41507)
code injection in remote (CVE-2026-41507). Successful exploitation can lead to full system takeover.
ROOT-OS-DEBIAN-13-CVE-2026-31594 Vulnerability in rootio-linux (ROOT-OS-DEBIAN-13-CVE-2026-31594)
vulnerability in rootio-linux (ROOT-OS-DEBIAN-13-CVE-2026-31594). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `6.12.90-2.root.io.130, 6.12.90-2.root.io.131, 6.12.90-2.root.io.132, 6.12.90-2.root.io.133, 6.12.90-2.root.io.134, 6.12.90-2.root.io.135, 6.12.90-2.root.io.136, 6.12.90-2.root.io.137, 6.12.90-2.root.io.138` or later.
ROOT-OS-DEBIAN-13-CVE-2026-23100 Vulnerability in rootio-linux (ROOT-OS-DEBIAN-13-CVE-2026-23100)
vulnerability in rootio-linux (ROOT-OS-DEBIAN-13-CVE-2026-23100). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `6.12.90-2.root.io.130, 6.12.90-2.root.io.131, 6.12.90-2.root.io.132, 6.12.90-2.root.io.133, 6.12.90-2.root.io.134, 6.12.90-2.root.io.135, 6.12.90-2.root.io.136, 6.12.90-2.root.io.137, 6.12.90-2.root.io.138` or later.
ROOT-OS-DEBIAN-13-CVE-2025-38512 Vulnerability in rootio-linux (ROOT-OS-DEBIAN-13-CVE-2025-38512)
vulnerability in rootio-linux (ROOT-OS-DEBIAN-13-CVE-2025-38512). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `6.12.90-2.root.io.130, 6.12.90-2.root.io.131, 6.12.90-2.root.io.132, 6.12.90-2.root.io.133, 6.12.90-2.root.io.134, 6.12.90-2.root.io.135, 6.12.90-2.root.io.136, 6.12.90-2.root.io.137, 6.12.90-2.root.io.138` or later.
ROOT-OS-DEBIAN-13-CVE-2026-23422 Vulnerability in rootio-linux (ROOT-OS-DEBIAN-13-CVE-2026-23422)
vulnerability in rootio-linux (ROOT-OS-DEBIAN-13-CVE-2026-23422). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `6.12.90-2.root.io.130, 6.12.90-2.root.io.131, 6.12.90-2.root.io.132, 6.12.90-2.root.io.133, 6.12.90-2.root.io.134, 6.12.90-2.root.io.135, 6.12.90-2.root.io.136, 6.12.90-2.root.io.137, 6.12.90-2.root.io.138` or later.
ROOT-OS-DEBIAN-13-CVE-2025-71071 Vulnerability in rootio-linux (ROOT-OS-DEBIAN-13-CVE-2025-71071)
vulnerability in rootio-linux (ROOT-OS-DEBIAN-13-CVE-2025-71071). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `6.12.90-2.root.io.130, 6.12.90-2.root.io.131, 6.12.90-2.root.io.132, 6.12.90-2.root.io.133, 6.12.90-2.root.io.134, 6.12.90-2.root.io.135, 6.12.90-2.root.io.136, 6.12.90-2.root.io.137, 6.12.90-2.root.io.138` or later.
ROOT-OS-DEBIAN-13-CVE-2026-23086 Vulnerability in rootio-linux (ROOT-OS-DEBIAN-13-CVE-2026-23086)
vulnerability in rootio-linux (ROOT-OS-DEBIAN-13-CVE-2026-23086). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `6.12.90-2.root.io.130, 6.12.90-2.root.io.131, 6.12.90-2.root.io.132, 6.12.90-2.root.io.133, 6.12.90-2.root.io.134, 6.12.90-2.root.io.135, 6.12.90-2.root.io.136, 6.12.90-2.root.io.137, 6.12.90-2.root.io.138` or later.
ROOT-OS-DEBIAN-13-CVE-2025-21949 Vulnerability in rootio-linux (ROOT-OS-DEBIAN-13-CVE-2025-21949)
vulnerability in rootio-linux (ROOT-OS-DEBIAN-13-CVE-2025-21949). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `6.12.90-2.root.io.130, 6.12.90-2.root.io.131, 6.12.90-2.root.io.132, 6.12.90-2.root.io.133, 6.12.90-2.root.io.134, 6.12.90-2.root.io.135, 6.12.90-2.root.io.136, 6.12.90-2.root.io.137, 6.12.90-2.root.io.138` or later.
ROOT-OS-DEBIAN-13-CVE-2019-16232 Vulnerability in rootio-linux (ROOT-OS-DEBIAN-13-CVE-2019-16232)
vulnerability in rootio-linux (ROOT-OS-DEBIAN-13-CVE-2019-16232). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `6.12.90-2.root.io.130, 6.12.90-2.root.io.131, 6.12.90-2.root.io.132, 6.12.90-2.root.io.133, 6.12.90-2.root.io.134, 6.12.90-2.root.io.135, 6.12.90-2.root.io.136, 6.12.90-2.root.io.137, 6.12.90-2.root.io.138` or later.
ROOT-OS-DEBIAN-13-CVE-2025-38612 Vulnerability in rootio-linux (ROOT-OS-DEBIAN-13-CVE-2025-38612)
vulnerability in rootio-linux (ROOT-OS-DEBIAN-13-CVE-2025-38612). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `6.12.90-2.root.io.130, 6.12.90-2.root.io.131, 6.12.90-2.root.io.132, 6.12.90-2.root.io.133, 6.12.90-2.root.io.134, 6.12.90-2.root.io.135, 6.12.90-2.root.io.136, 6.12.90-2.root.io.137, 6.12.90-2.root.io.138` or later.
ROOT-OS-DEBIAN-13-CVE-2026-23450 Vulnerability in rootio-linux (ROOT-OS-DEBIAN-13-CVE-2026-23450)
vulnerability in rootio-linux (ROOT-OS-DEBIAN-13-CVE-2026-23450). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `6.12.90-2.root.io.130, 6.12.90-2.root.io.131, 6.12.90-2.root.io.132, 6.12.90-2.root.io.133, 6.12.90-2.root.io.134, 6.12.90-2.root.io.135, 6.12.90-2.root.io.136, 6.12.90-2.root.io.137, 6.12.90-2.root.io.138` or later.
ROOT-OS-DEBIAN-13-CVE-2025-68174 Vulnerability in rootio-linux (ROOT-OS-DEBIAN-13-CVE-2025-68174)
vulnerability in rootio-linux (ROOT-OS-DEBIAN-13-CVE-2025-68174). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `6.12.90-2.root.io.130, 6.12.90-2.root.io.131, 6.12.90-2.root.io.132, 6.12.90-2.root.io.133, 6.12.90-2.root.io.134, 6.12.90-2.root.io.135, 6.12.90-2.root.io.136, 6.12.90-2.root.io.137, 6.12.90-2.root.io.138` or later.
ROOT-OS-DEBIAN-13-CVE-2026-23035 Vulnerability in rootio-linux (ROOT-OS-DEBIAN-13-CVE-2026-23035)
vulnerability in rootio-linux (ROOT-OS-DEBIAN-13-CVE-2026-23035). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `6.12.90-2.root.io.130, 6.12.90-2.root.io.131, 6.12.90-2.root.io.132, 6.12.90-2.root.io.133, 6.12.90-2.root.io.134, 6.12.90-2.root.io.135, 6.12.90-2.root.io.136, 6.12.90-2.root.io.137, 6.12.90-2.root.io.138` or later.
ROOT-OS-DEBIAN-13-CVE-2025-38653 Vulnerability in rootio-linux (ROOT-OS-DEBIAN-13-CVE-2025-38653)
vulnerability in rootio-linux (ROOT-OS-DEBIAN-13-CVE-2025-38653). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `6.12.90-2.root.io.130, 6.12.90-2.root.io.131, 6.12.90-2.root.io.132, 6.12.90-2.root.io.133, 6.12.90-2.root.io.134, 6.12.90-2.root.io.135, 6.12.90-2.root.io.136, 6.12.90-2.root.io.137, 6.12.90-2.root.io.138` or later.
ROOT-OS-DEBIAN-13-CVE-2025-22106 Vulnerability in rootio-linux (ROOT-OS-DEBIAN-13-CVE-2025-22106)
vulnerability in rootio-linux (ROOT-OS-DEBIAN-13-CVE-2025-22106). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `6.12.90-2.root.io.130, 6.12.90-2.root.io.131, 6.12.90-2.root.io.132, 6.12.90-2.root.io.133, 6.12.90-2.root.io.134, 6.12.90-2.root.io.135, 6.12.90-2.root.io.136, 6.12.90-2.root.io.137, 6.12.90-2.root.io.138` or later.
ROOT-OS-DEBIAN-13-CVE-2026-31717 Vulnerability in rootio-linux (ROOT-OS-DEBIAN-13-CVE-2026-31717)
vulnerability in rootio-linux (ROOT-OS-DEBIAN-13-CVE-2026-31717). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `6.12.90-2.root.io.130, 6.12.90-2.root.io.131, 6.12.90-2.root.io.132, 6.12.90-2.root.io.133, 6.12.90-2.root.io.134, 6.12.90-2.root.io.135, 6.12.90-2.root.io.136, 6.12.90-2.root.io.137, 6.12.90-2.root.io.138` or later.
ROOT-OS-DEBIAN-13-CVE-2026-31533 Vulnerability in rootio-linux (ROOT-OS-DEBIAN-13-CVE-2026-31533)
vulnerability in rootio-linux (ROOT-OS-DEBIAN-13-CVE-2026-31533). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `6.12.90-2.root.io.130, 6.12.90-2.root.io.131, 6.12.90-2.root.io.132, 6.12.90-2.root.io.133, 6.12.90-2.root.io.134, 6.12.90-2.root.io.135, 6.12.90-2.root.io.136, 6.12.90-2.root.io.137, 6.12.90-2.root.io.138` or later.
ROOT-OS-DEBIAN-13-CVE-2025-40055 Vulnerability in rootio-linux (ROOT-OS-DEBIAN-13-CVE-2025-40055)
vulnerability in rootio-linux (ROOT-OS-DEBIAN-13-CVE-2025-40055). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `6.12.90-2.root.io.130, 6.12.90-2.root.io.131, 6.12.90-2.root.io.132, 6.12.90-2.root.io.133, 6.12.90-2.root.io.134, 6.12.90-2.root.io.135, 6.12.90-2.root.io.136, 6.12.90-2.root.io.137, 6.12.90-2.root.io.138` or later.
ROOT-OS-DEBIAN-13-CVE-2026-23377 Vulnerability in rootio-linux (ROOT-OS-DEBIAN-13-CVE-2026-23377)
vulnerability in rootio-linux (ROOT-OS-DEBIAN-13-CVE-2026-23377). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `6.12.90-2.root.io.130, 6.12.90-2.root.io.131, 6.12.90-2.root.io.132, 6.12.90-2.root.io.133, 6.12.90-2.root.io.134, 6.12.90-2.root.io.135, 6.12.90-2.root.io.136, 6.12.90-2.root.io.137, 6.12.90-2.root.io.138` or later.
ROOT-OS-DEBIAN-13-CVE-2025-38545 Vulnerability in rootio-linux (ROOT-OS-DEBIAN-13-CVE-2025-38545)
vulnerability in rootio-linux (ROOT-OS-DEBIAN-13-CVE-2025-38545). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `6.12.90-2.root.io.130, 6.12.90-2.root.io.131, 6.12.90-2.root.io.132, 6.12.90-2.root.io.133, 6.12.90-2.root.io.134, 6.12.90-2.root.io.135, 6.12.90-2.root.io.136, 6.12.90-2.root.io.137, 6.12.90-2.root.io.138` or later.

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →