Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

ID Title
ECHO-a7b5-9790-ee2f ECHO-a7b5-9790-ee2f
ECHO-9581-aff6-f7db ECHO-9581-aff6-f7db
ECHO-f8ed-8dc1-2115 ECHO-f8ed-8dc1-2115
ECHO-ad59-7247-d6bc ECHO-ad59-7247-d6bc
ECHO-1e6e-2e1a-3941 ECHO-1e6e-2e1a-3941
MINI-wpqv-82xp-97fv MINI-wpqv-82xp-97fv
MINI-569m-2x4w-ff89 MINI-569m-2x4w-ff89
MINI-mmvx-rm89-m3j8 MINI-mmvx-rm89-m3j8
MINI-8pq3-69m2-r59x MINI-8pq3-69m2-r59x
MINI-623g-8r98-695g MINI-623g-8r98-695g
MINI-pgfq-66r7-m866 MINI-pgfq-66r7-m866
CVE-2026-55170 Vulnerability in github.com/openfga/openfga (CVE-2026-55170)
vulnerability in github.com/openfga/openfga (CVE-2026-55170). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.18.0` or later.
CVE-2026-55093 Out-of-Bounds Read in tract-nnef (CVE-2026-55093)
vulnerability in tract-nnef (CVE-2026-55093). Risk of unauthorized operations or information disclosure. Exploitable via ``DatLoader``. Mitigation: upgrade to `0.21.16` or later.
CVE-2026-54711 Vulnerability in pghoard (CVE-2026-54711)
vulnerability in pghoard (CVE-2026-54711). Risk of unauthorized operations or information disclosure.
MINI-2r3g-qfj3-33rj MINI-2r3g-qfj3-33rj
CVE-2026-54695 Vulnerability in pipecat-ai (CVE-2026-54695)
vulnerability in pipecat-ai (CVE-2026-54695). Risk of unauthorized operations or information disclosure. Exploitable via `POST /start`. Mitigation: upgrade to `1.4.0` or later.
CVE-2026-55701 Authorization Flaw in github.com/open-telemetry/opentelemetry-collector-contrib/receiver/githubreceiver (CVE-2026-55701)
vulnerability in github.com/open-telemetry/opentelemetry-collector-contrib/receiver/githubreceiver (CVE-2026-55701). Risk of unauthorized operations or information disclosure. Exploitable via ``required_headers``. Mitigation: upgrade to `0.151.0` or later.
CVE-2026-54005 Vulnerability in getkirby/cms (CVE-2026-54005)
vulnerability in getkirby/cms (CVE-2026-54005). Risk of unauthorized operations or information disclosure. Exploitable via ``pages.access``. Mitigation: upgrade to `5.4.4` or later.
CVE-2026-54004 Vulnerability in getkirby/cms (CVE-2026-54004)
vulnerability in getkirby/cms (CVE-2026-54004). Risk of unauthorized operations or information disclosure. Exploitable via ``content.fileRedirects``. Mitigation: upgrade to `5.4.4` or later.
CVE-2026-54003 Vulnerability in getkirby/cms (CVE-2026-54003)
vulnerability in getkirby/cms (CVE-2026-54003). Risk of unauthorized operations or information disclosure. Exploitable via ``panel.install``. Mitigation: upgrade to `5.4.4` or later.
MINI-9h69-273x-6r9c MINI-9h69-273x-6r9c
CVE-2026-54002 Cross-Site Scripting (XSS) in getkirby/cms (CVE-2026-54002)
cross-site scripting in getkirby/cms (CVE-2026-54002). Risk of unauthorized operations or information disclosure. Exploitable via ``writer``. Mitigation: upgrade to `5.4.4` or later.
CVE-2026-50188 Vulnerability in getkirby/cms (CVE-2026-50188)
vulnerability in getkirby/cms (CVE-2026-50188). Risk of unauthorized operations or information disclosure. Exploitable via ``headers``. Mitigation: upgrade to `5.4.4` or later.
CVE-2026-49276 Vulnerability in getkirby/cms (CVE-2026-49276)
vulnerability in getkirby/cms (CVE-2026-49276). Risk of unauthorized operations or information disclosure. Exploitable via ``writer``. Mitigation: upgrade to `5.4.4` or later.
MINI-h44j-gpw8-hm37 MINI-h44j-gpw8-hm37
CVE-2026-49274 Vulnerability in getkirby/cms (CVE-2026-49274)
vulnerability in getkirby/cms (CVE-2026-49274). Risk of unauthorized operations or information disclosure. Exploitable via ``pages``. Mitigation: upgrade to `5.4.4` or later.
CVE-2026-47256 Path Traversal in github.com/open-telemetry/opentelemetry-collector-contrib/exporter/sentryexporter (CVE-2026-47256)
path traversal in github.com/open-telemetry/opentelemetry-collector-contrib/exporter/sentryexporter (CVE-2026-47256). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.154.0` or later.
CVE-2026-44727 Cross-Site Scripting (XSS) in jupyter-server (CVE-2026-44727)
cross-site scripting in jupyter-server (CVE-2026-44727). Risk of unauthorized operations or information disclosure. Exploitable via ``nbconvert.HTMLExporter``. Mitigation: upgrade to `2.20.0` or later.
CVE-2026-12567 Path Traversal in bbot (CVE-2026-12567)
path traversal in bbot (CVE-2026-12567). Risk of unauthorized operations or information disclosure. Exploitable via ``github_workflows``. Mitigation: upgrade to `2.8.5` or later.
CVE-2026-12568 Out-of-Bounds Read in bbot (CVE-2026-12568)
vulnerability in bbot (CVE-2026-12568). Data can be tampered with by attackers. Exploitable via ``postman_download``. Mitigation: upgrade to `2.8.6` or later.
CVE-2026-12566 Vulnerability in bbot (CVE-2026-12566)
vulnerability in bbot (CVE-2026-12566). Risk of unauthorized operations or information disclosure. Exploitable via ``docker_pull``. Mitigation: upgrade to `2.8.5` or later.
CVE-2026-12565 Path Traversal in bbot (CVE-2026-12565)
path traversal in bbot (CVE-2026-12565). Data can be tampered with by attackers. Exploitable via ``unarchive``. Mitigation: upgrade to `2.8.5` or later.
MINI-69g5-g8w4-vw9m MINI-69g5-g8w4-vw9m
MINI-cq89-j96f-99q3 MINI-cq89-j96f-99q3
MINI-9cv2-94ww-qvf6 MINI-9cv2-94ww-qvf6
MINI-wcfx-jfhq-w236 MINI-wcfx-jfhq-w236
MINI-w3cw-8527-2rgh MINI-w3cw-8527-2rgh
MINI-v339-cqjr-rxc8 MINI-v339-cqjr-rxc8
MINI-59pf-6wxg-j9px MINI-59pf-6wxg-j9px
MINI-4v7g-cv4p-4f4g MINI-4v7g-cv4p-4f4g
MINI-wc45-xj5v-vm8x MINI-wc45-xj5v-vm8x
MINI-97h9-956f-mmc3 MINI-97h9-956f-mmc3
MINI-jmqr-34gq-9ff8 MINI-jmqr-34gq-9ff8
MINI-5v95-jf79-m8hg MINI-5v95-jf79-m8hg
MINI-r35p-4589-rqwm MINI-r35p-4589-rqwm
MINI-765f-76fq-g8c4 MINI-765f-76fq-g8c4
MINI-jrhv-x772-ww7q MINI-jrhv-x772-ww7q
MINI-p432-42j3-fvpp MINI-p432-42j3-fvpp
MINI-q7v9-cwxc-6969 MINI-q7v9-cwxc-6969
MINI-h2gx-7m4w-5vch MINI-h2gx-7m4w-5vch

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →