Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| SUSE-SU-2026:2452-1 |
|
Security update for rootlesskit
Security update for rootlesskit
|
| SUSE-SU-2026:2451-1 |
|
Security update for rootlesskit
Security update for rootlesskit
|
| CVE-2026-41083 |
|
Vulnerability in ocaml (CVE-2026-41083)
vulnerability in ocaml (CVE-2026-41083). Confidential information can be exposed externally. Exploitable via ``Filename.quote_command``. Mitigation: upgrade to `4.14.4, 5.5.0, ce6d0f7b67145debec57e296dcc49d8619259198, 39d3f110eab62ab9f3013bb5f084af2dc3e3bb08, d5c65dc0034fbd75f10c6b54028e8b2740a7b189` or later.
|
| MINI-54gx-rj97-rrc8 |
|
MINI-54gx-rj97-rrc8 |
| SUSE-SU-2026:2450-1 |
|
Vulnerability in kernel-default (SUSE-SU-2026:2450-1)
vulnerability in kernel-default (SUSE-SU-2026:2450-1). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `4.12.14-122.317.1` or later.
|
| USN-8449-1 |
|
Vulnerability in ldns (USN-8449-1)
vulnerability in ldns (USN-8449-1). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.6.17-8ubuntu0.1+esm2` or later.
|
| MINI-jh32-6xj9-62q4 |
|
MINI-jh32-6xj9-62q4 |
| MINI-c6p5-qw5r-fm4x |
|
MINI-c6p5-qw5r-fm4x |
| MINI-jhmp-9jf2-v4gr |
|
MINI-jhmp-9jf2-v4gr |
| CVE-2026-34353 |
|
Vulnerability in ocaml (CVE-2026-34353)
vulnerability in ocaml (CVE-2026-34353). Confidential information can be exposed externally. Exploitable via ``caml_ba_reshape``. Mitigation: upgrade to `4.14.4, 1ec6b6e8ef9d30fc1d8bac71a6646c2ef78ea90b` or later.
|
| CVE-2026-55670 |
|
Vulnerability in github.com/zitadel/zitadel (CVE-2026-55670)
vulnerability in github.com/zitadel/zitadel (CVE-2026-55670). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.80.0-v2.20.0.20260615092437-6082e59d47c1` or later.
|
| GHSA-47qp-hqvx-6r3f |
|
Vulnerability in org.jline:jline-remote-telnet (GHSA-47qp-hqvx-6r3f)
vulnerability in org.jline:jline-remote-telnet (GHSA-47qp-hqvx-6r3f). Risk of unauthorized operations or information disclosure. Exploitable via ``HashMap``. Mitigation: upgrade to `4.2.1` or later.
|
| GHSA-2r2c-cx56-8933 |
|
Vulnerability in org.jline:jline-remote-telnet (GHSA-2r2c-cx56-8933)
vulnerability in org.jline:jline-remote-telnet (GHSA-2r2c-cx56-8933). Risk of unauthorized operations or information disclosure. Exploitable via ``Telnet``. Mitigation: upgrade to `4.2.1` or later.
|
| CVE-2026-55661 |
|
Cross-Site Scripting (XSS) in tinacms (CVE-2026-55661)
cross-site scripting in tinacms (CVE-2026-55661). Risk of unauthorized operations or information disclosure. Exploitable via ``url``. Mitigation: upgrade to `3.9.3` or later.
|
| GHSA-2c85-rfcc-g74j |
|
Vulnerability in io.karatelabs:karate-core (GHSA-2c85-rfcc-g74j)
vulnerability in io.karatelabs:karate-core (GHSA-2c85-rfcc-g74j). Risk of unauthorized operations or information disclosure. Exploitable via `POST /api/echo`. Mitigation: upgrade to `2.1.0` or later.
|
| CVE-2026-55617 |
|
Vulnerability in hydrooj (CVE-2026-55617)
vulnerability in hydrooj (CVE-2026-55617). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `5.0.2` or later.
|
| CVE-2026-55603 |
|
Vulnerability in http-proxy-middleware (CVE-2026-55603)
vulnerability in http-proxy-middleware (CVE-2026-55603). Data can be tampered with by attackers. Exploitable via ``req.body``. Mitigation: upgrade to `4.1.1` or later.
|
| CVE-2026-55602 |
|
Vulnerability in http-proxy-middleware (CVE-2026-55602)
vulnerability in http-proxy-middleware (CVE-2026-55602). Data can be tampered with by attackers. Exploitable via ``router``. Mitigation: upgrade to `2.0.10` or later.
|
| CVE-2026-55254 |
|
Vulnerability in NCalc.Core (CVE-2026-55254)
vulnerability in NCalc.Core (CVE-2026-55254). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `6.1.1` or later.
|
| CVE-2026-55388 |
|
Vulnerability in piscina (CVE-2026-55388)
vulnerability in piscina (CVE-2026-55388). Successful exploitation can lead to full system takeover. Exploitable via `POST /upload`. Mitigation: upgrade to `6.0.0-rc.2` or later.
|
| CVE-2026-55887 |
|
Vulnerability in github.com/docker/mcp-gateway (CVE-2026-55887)
vulnerability in github.com/docker/mcp-gateway (CVE-2026-55887). Risk of unauthorized operations or information disclosure. Exploitable via ``io.docker.server.metadata``. Mitigation: upgrade to `0.42.2` or later.
|
| CVE-2026-55886 |
|
Vulnerability in jodit (CVE-2026-55886)
vulnerability in jodit (CVE-2026-55886). Risk of unauthorized operations or information disclosure. Exploitable via ``chain``. Mitigation: upgrade to `4.12.26` or later.
|
| CVE-2026-55229 |
|
SSRF (Server-Side Request Forgery) in github.com/gotenberg/gotenberg/v8 (CVE-2026-55229)
SSRF in github.com/gotenberg/gotenberg/v8 (CVE-2026-55229). Confidential information can be exposed externally. Exploitable via `GET /secretendpoint`. Mitigation: upgrade to `8.34.0` or later.
|
| CVE-2026-55226 |
|
Privilege Escalation in io.strimzi:strimzi (CVE-2026-55226)
vulnerability in io.strimzi:strimzi (CVE-2026-55226). Confidential information can be exposed externally. Exploitable via ``Kafka``. Mitigation: upgrade to `1.0.1` or later.
|
| CVE-2026-55225 |
|
Privilege Escalation in io.strimzi:strimzi (CVE-2026-55225)
vulnerability in io.strimzi:strimzi (CVE-2026-55225). Successful exploitation can lead to full system takeover. Exploitable via ``watchedNamespace``. Mitigation: upgrade to `1.0.1` or later.
|
| MINI-2w8c-3p3p-48fc |
|
MINI-2w8c-3p3p-48fc |
| MINI-9484-4mc9-c234 |
|
MINI-9484-4mc9-c234 |
| MINI-v95q-g5x6-j2vc |
|
MINI-v95q-g5x6-j2vc |
| MINI-w796-p7jq-2prh |
|
MINI-w796-p7jq-2prh |
| MINI-92wj-6f6q-pq3j |
|
MINI-92wj-6f6q-pq3j |
| CVE-2026-55671 |
|
SSRF (Server-Side Request Forgery) in github.com/zitadel/zitadel (CVE-2026-55671)
SSRF in github.com/zitadel/zitadel (CVE-2026-55671). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.80.0-v2.20.0.20260615133614-8e82ec1cb9a2` or later.
|
| MINI-f3m7-2pp9-xhv7 |
|
MINI-f3m7-2pp9-xhv7 |
| MINI-mj4j-6933-36j9 |
|
MINI-mj4j-6933-36j9 |
| MINI-32h7-jwx3-rrpf |
|
MINI-32h7-jwx3-rrpf |
| MINI-rpx9-5mfc-wj6x |
|
MINI-rpx9-5mfc-wj6x |
| MINI-mhfc-vrfh-4gcg |
|
MINI-mhfc-vrfh-4gcg |
| MINI-g3pm-wq45-j4mf |
|
MINI-g3pm-wq45-j4mf |
| MINI-3hj7-5hx3-r3fr |
|
MINI-3hj7-5hx3-r3fr |
| MINI-pwp6-vf2j-g94c |
|
MINI-pwp6-vf2j-g94c |
| MINI-jj3w-f836-4xmq |
|
MINI-jj3w-f836-4xmq |
| MINI-8cv3-vqrm-38wr |
|
MINI-8cv3-vqrm-38wr |
| MINI-mwfr-87jr-6qrw |
|
MINI-mwfr-87jr-6qrw |
| MINI-69fx-xvjw-73r4 |
|
MINI-69fx-xvjw-73r4 |
| SUSE-SU-2026:2449-1 |
|
Security update for krb5
Security update for krb5
|
| ROOT-APP-NPM-CVE-2018-16469 |
|
Vulnerability in @rootio/merge (ROOT-APP-NPM-CVE-2018-16469)
vulnerability in @rootio/merge (ROOT-APP-NPM-CVE-2018-16469). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.2.1-root.io.1, 1.2.1-root.io.2` or later.
|
| CVE-2026-55746 |
|
Cross-Site Scripting (XSS) in cotonti/cotonti (CVE-2026-55746)
cross-site scripting in cotonti/cotonti (CVE-2026-55746). Confidential information can be exposed externally.
|
| CVE-2026-55745 |
|
Cross-Site Request Forgery (CSRF) in cotonti/cotonti (CVE-2026-55745)
vulnerability in cotonti/cotonti (CVE-2026-55745). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-9815 |
|
Vulnerability in wordpress (CVE-2026-9815)
vulnerability in wordpress (CVE-2026-9815). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-55742 |
|
Cross-Site Request Forgery (CSRF) in cotonti/cotonti (CVE-2026-55742)
vulnerability in cotonti/cotonti (CVE-2026-55742). Successful exploitation can lead to full system takeover.
|
| CVE-2026-12136 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-12136)
cross-site scripting in wordpress (CVE-2026-12136). Risk of unauthorized operations or information disclosure.
|