Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| BELL-CVE-2026-48933 |
|
BELL-CVE-2026-48933 |
| BELL-CVE-2026-48935 |
|
BELL-CVE-2026-48935 |
| BELL-CVE-2026-48930 |
|
BELL-CVE-2026-48930 |
| BELL-CVE-2026-48934 |
|
BELL-CVE-2026-48934 |
| BELL-CVE-2026-48928 |
|
BELL-CVE-2026-48928 |
| BELL-CVE-2026-48619 |
|
BELL-CVE-2026-48619 |
| BELL-CVE-2026-48931 |
|
BELL-CVE-2026-48931 |
| BELL-CVE-2026-48618 |
|
BELL-CVE-2026-48618 |
| BELL-CVE-2026-48615 |
|
BELL-CVE-2026-48615 |
| BELL-CVE-2026-48142 |
|
BELL-CVE-2026-48142 |
| BELL-CVE-2026-42055 |
|
BELL-CVE-2026-42055 |
| MAL-2026-6234 |
|
Vulnerability in yian666aikf (MAL-2026-6234)
vulnerability in yian666aikf (MAL-2026-6234). Risk of unauthorized operations or information disclosure.
|
| MAL-2026-6235 |
|
Vulnerability in yianzzkf6687 (MAL-2026-6235)
vulnerability in yianzzkf6687 (MAL-2026-6235). Risk of unauthorized operations or information disclosure. Exploitable via ``net``.
|
| CVE-2026-9265 |
|
Out-of-Bounds Read in CVE-2026-9265 (CVE-2026-9265)
vulnerability in CVE-2026-9265 (CVE-2026-9265). Confidential information can be exposed externally.
|
| CVE-2026-9843 |
|
Path Traversal in wordpress (CVE-2026-9843)
path traversal in wordpress (CVE-2026-9843). Data can be tampered with by attackers.
|
| ECHO-e82f-e0e2-2625 |
|
ECHO-e82f-e0e2-2625 |
| ECHO-aa4f-978c-e8b4 |
|
ECHO-aa4f-978c-e8b4 |
| UBUNTU-CVE-2026-9265 |
|
Vulnerability in libcrypt-openssl-pkcs12-perl (UBUNTU-CVE-2026-9265)
vulnerability in libcrypt-openssl-pkcs12-perl (UBUNTU-CVE-2026-9265). Confidential information can be exposed externally.
|
| CVE-2026-56216 |
|
Privilege Escalation in CVE-2026-56216 (CVE-2026-56216)
vulnerability in CVE-2026-56216 (CVE-2026-56216). Successful exploitation can lead to full system takeover. Exploitable via `POST /functions/v1/apikey`.
|
| CVE-2026-56215 |
|
Vulnerability in CVE-2026-56215 (CVE-2026-56215)
vulnerability in CVE-2026-56215 (CVE-2026-56215). Confidential information can be exposed externally.
|
| CVE-2026-56214 |
|
Information Disclosure in CVE-2026-56214 (CVE-2026-56214)
vulnerability in CVE-2026-56214 (CVE-2026-56214). Confidential information can be exposed externally.
|
| CVE-2026-56213 |
|
Vulnerability in CVE-2026-56213 (CVE-2026-56213)
vulnerability in CVE-2026-56213 (CVE-2026-56213). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-56212 |
|
Privilege Escalation in CVE-2026-56212 (CVE-2026-56212)
vulnerability in CVE-2026-56212 (CVE-2026-56212). Risk of unauthorized operations or information disclosure.
|
| MAL-2026-6233 |
|
Vulnerability in fluent-dashboard-panel-metrics (MAL-2026-6233)
vulnerability in fluent-dashboard-panel-metrics (MAL-2026-6233). Risk of unauthorized operations or information disclosure. Exploitable via ``__all__``.
|
| CVE-2026-11551 |
|
Vulnerability in wordpress (CVE-2026-11551)
vulnerability in wordpress (CVE-2026-11551). Successful exploitation can lead to full system takeover.
|
| openSUSE-SU-2026:11071-1 |
|
Vulnerability in chromium (openSUSE-SU-2026:11071-1)
vulnerability in chromium (openSUSE-SU-2026:11071-1). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `149.0.7827.155-1.1` or later.
|
| CGA-v43f-5gf4-32gg |
|
CGA-v43f-5gf4-32gg |
| CGA-jqhj-9577-3g66 |
|
CGA-jqhj-9577-3g66 |
| CGA-6p2h-7vrw-h4w8 |
|
CGA-6p2h-7vrw-h4w8 |
| MAL-2026-6231 |
|
Vulnerability in improvado-layout-panel-metrics (MAL-2026-6231)
vulnerability in improvado-layout-panel-metrics (MAL-2026-6231). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-56082 |
|
Vulnerability in dos (CVE-2026-56082)
vulnerability in dos (CVE-2026-56082). Data can be tampered with by attackers.
|
| CVE-2026-56081 |
|
Vulnerability in CVE-2026-56081 (CVE-2026-56081)
vulnerability in CVE-2026-56081 (CVE-2026-56081). Confidential information can be exposed externally.
|
| CVE-2026-56080 |
|
Authentication Bypass in dos (CVE-2026-56080)
authentication bypass in dos (CVE-2026-56080). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-56079 |
|
Information Disclosure in CVE-2026-56079 (CVE-2026-56079)
vulnerability in CVE-2026-56079 (CVE-2026-56079). Confidential information can be exposed externally.
|
| CVE-2026-56073 |
|
Vulnerability in CVE-2026-56073 (CVE-2026-56073)
vulnerability in CVE-2026-56073 (CVE-2026-56073). Confidential information can be exposed externally.
|
| GHSA-869j-r97x-hx2g |
|
Path Traversal in aqt (GHSA-869j-r97x-hx2g)
path traversal in aqt (GHSA-869j-r97x-hx2g). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `25.9.3` or later.
|
| GHSA-jv2j-mqmw-xvv5 |
|
Vulnerability in surrealdb (GHSA-jv2j-mqmw-xvv5)
vulnerability in surrealdb (GHSA-jv2j-mqmw-xvv5). Risk of unauthorized operations or information disclosure. Exploitable via ``expr_recursion_limit``. Mitigation: upgrade to `3.1.5` or later.
|
| GHSA-hv6h-hc26-q48p |
|
Authorization Flaw in surrealdb (GHSA-hv6h-hc26-q48p)
vulnerability in surrealdb (GHSA-hv6h-hc26-q48p). Risk of unauthorized operations or information disclosure. Exploitable via ``SELECT``. Mitigation: upgrade to `3.1.5` or later.
|
| GHSA-h4h3-3rfj-x6fq |
|
Information Disclosure in surrealdb (GHSA-h4h3-3rfj-x6fq)
vulnerability in surrealdb (GHSA-h4h3-3rfj-x6fq). Risk of unauthorized operations or information disclosure. Exploitable via ``null``. Mitigation: upgrade to `3.1.5` or later.
|
| GHSA-cc8f-fcx3-gpjr |
|
Vulnerability in surrealdb (GHSA-cc8f-fcx3-gpjr)
vulnerability in surrealdb (GHSA-cc8f-fcx3-gpjr). Confidential information can be exposed externally. Exploitable via ``mapper``. Mitigation: upgrade to `3.1.5` or later.
|
| GHSA-h5rg-8p7f-47g2 |
|
SSRF (Server-Side Request Forgery) in surrealdb (GHSA-h5rg-8p7f-47g2)
SSRF in surrealdb (GHSA-h5rg-8p7f-47g2). Risk of unauthorized operations or information disclosure. Exploitable via ``reqwest``. Mitigation: upgrade to `3.1.5` or later.
|
| GHSA-4xgf-cpjx-pc3j |
|
Path Traversal in pydantic-settings (GHSA-4xgf-cpjx-pc3j)
path traversal in pydantic-settings (GHSA-4xgf-cpjx-pc3j). Risk of unauthorized operations or information disclosure. Exploitable via ``NestedSecretsSettingsSource``. Mitigation: upgrade to `2.14.2` or later.
|
| GHSA-g2gw-q38m-vjfc |
|
SSRF (Server-Side Request Forgery) in @merill/lokka (GHSA-g2gw-q38m-vjfc)
SSRF in @merill/lokka (GHSA-g2gw-q38m-vjfc). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.1.2` or later.
|
| GHSA-h5x8-xp6m-x6q4 |
|
Vulnerability in @jhb.software/payload-cloudinary-plugin (GHSA-h5x8-xp6m-x6q4)
vulnerability in @jhb.software/payload-cloudinary-plugin (GHSA-h5x8-xp6m-x6q4). Data can be tampered with by attackers. Exploitable via `POST /api/cloudinary-generate-signature`. Mitigation: upgrade to `0.4.0` or later.
|
| GHSA-f4xh-w4cj-qxq8 |
|
Path Traversal in langsmith (GHSA-f4xh-w4cj-qxq8)
path traversal in langsmith (GHSA-f4xh-w4cj-qxq8). Risk of unauthorized operations or information disclosure. Exploitable via ``TracingMiddleware``. Mitigation: upgrade to `0.8.18` or later.
|
| GHSA-c3xh-98xp-6qhf |
|
OS Command Injection in gouef/githubtoplanguages (GHSA-c3xh-98xp-6qhf)
OS command injection in gouef/githubtoplanguages (GHSA-c3xh-98xp-6qhf). Risk of unauthorized operations or information disclosure. Exploitable via ``github.event.issue.title``. Mitigation: upgrade to `1.1.4` or later.
|
| GHSA-4cc2-g9w2-fhf6 |
|
SSRF (Server-Side Request Forgery) in zeep (GHSA-4cc2-g9w2-fhf6)
SSRF in zeep (GHSA-4cc2-g9w2-fhf6). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `4.3.3` or later.
|
| GHSA-cw6h-ffmh-x6vh |
|
Path Traversal in aqt (GHSA-cw6h-ffmh-x6vh)
path traversal in aqt (GHSA-cw6h-ffmh-x6vh). Risk of unauthorized operations or information disclosure. Exploitable via ``getImageForOcclusion``. Mitigation: upgrade to `25.9.4` or later.
|
| GHSA-wvrh-2f4m-924v |
|
Vulnerability in ChatterBot (GHSA-wvrh-2f4m-924v)
vulnerability in ChatterBot (GHSA-wvrh-2f4m-924v). Risk of unauthorized operations or information disclosure. Exploitable via ``makedirs``. Mitigation: upgrade to `1.2.14` or later.
|
| CVE-2026-57168 |
|
Vulnerability in io.openremote:openremote-manager (CVE-2026-57168)
vulnerability in io.openremote:openremote-manager (CVE-2026-57168). Risk of unauthorized operations or information disclosure. Exploitable via `DELETE /api/smartcity/alarm`. Mitigation: upgrade to `1.25.0` or later.
|